logo

The npm incident frightened everyone, but ended up being nothing to fret about

ID: 3e438444-e98d-5042-bd5a-f56faa925206

STIX ID: report--3e438444-e98d-5042-bd5a-f56faa925206

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2025-09-10

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

An npm supply-chain compromise occurred after an attacker used social engineering to hijack a maintainer's account and publish malicious updates to widely used packages (including ansi-styles, debug, chalk and supports-color) that attempted to intercept and redirect cryptocurrency activity; the infected versions were available for up to six hours, caused minimal confirmed financial loss (~$1k), and were quickly detected and remediated by the community and npm.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.