When Dependencies Turn Dangerous: Responding to the NPM Supply Chain Attack
ID: dbb21164-d888-5006-bbfa-cf54c8f3b97c
STIX ID: report--dbb21164-d888-5006-bbfa-cf54c8f3b97c
Feed Name: Qualys Blog
**Supply-chain compromise of 18 popular npm packages (including chalk, debug, strip-ansi, etc.) published via a targeted phishing attack on a maintainer; malicious versions (listed by package and version) contained obfuscated JavaScript that silently rewrote cryptocurrency transactions and risked widespread downstream contamination across environments given ~2.6 billion weekly downloads — the report outlines detection, containment steps (lockfile checks, cache purges, blocklisting, runtime hunts), and how Qualys SCA, TruRisk, Attack Path, and CDR can prioritize and stop active exploitation.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
