More packages poisoned in npm attack, but would-be crypto thieves left pocket change
ID: 9396c2e9-d264-5b3d-8a39-6f2893e367a4
STIX ID: report--9396c2e9-d264-5b3d-8a39-6f2893e367a4
Feed Name: The Register (Security)
A phishing-driven supply-chain attack compromised an npm maintainer’s account, allowing attackers to publish malware-laced versions of widely used packages (initially 18 Qix packages, later additional DuckDB and coveops/abi packages). The malicious releases were found in about 10% of cloud environments and could still be available for download; despite large scale potential, on-chain analysis shows only around $925 stolen, and researchers warn organizations to assume malicious package versions may persist and to harden supply-chain and credential defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
