The npm incident frightened everyone, but ended up being nothing to fret about
ID: 3e438444-e98d-5042-bd5a-f56faa925206
STIX ID: report--3e438444-e98d-5042-bd5a-f56faa925206
Feed Name: CyberScoop
Threat Score
An npm supply-chain compromise occurred after an attacker used social engineering to hijack a maintainer's account and publish malicious updates to widely used packages (including ansi-styles, debug, chalk and supports-color) that attempted to intercept and redirect cryptocurrency activity; the infected versions were available for up to six hours, caused minimal confirmed financial loss (~$1k), and were quickly detected and remediated by the community and npm.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
