logo

When Dependencies Turn Dangerous: Responding to the NPM Supply Chain Attack

ID: dbb21164-d888-5006-bbfa-cf54c8f3b97c

STIX ID: report--dbb21164-d888-5006-bbfa-cf54c8f3b97c

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2025-09-10

Date Updated: 2026-04-28

Author: Abhinav Mishra

...
...

**Supply-chain compromise of 18 popular npm packages (including chalk, debug, strip-ansi, etc.) published via a targeted phishing attack on a maintainer; malicious versions (listed by package and version) contained obfuscated JavaScript that silently rewrote cryptocurrency transactions and risked widespread downstream contamination across environments given ~2.6 billion weekly downloads — the report outlines detection, containment steps (lockfile checks, cache purges, blocklisting, runtime hunts), and how Qualys SCA, TruRisk, Attack Path, and CDR can prioritize and stop active exploitation.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.