logo

npm Supply Chain Attack

ID: e6db48b2-fcfc-5a7d-a1ff-f79651bdd98c

STIX ID: report--e6db48b2-fcfc-5a7d-a1ff-f79651bdd98c

Feed Name: FortiGuard Threat Signals

Threat Score
90/100

Date Published: 2025-10-15

Date Updated: 2026-07-28

...
...

On September 8 and November 24, 2025, a supply-chain campaign attributed to "Shai Hulud" compromised an npm maintainer and multiple developer services (Zapier, ENS, AsyncAPI, PostHog, Postman), publishing malicious package versions and deploying a self‑replicating worm that impacted over 500 packages and roughly 25,000 repositories across ~350 users; the malware scanned for and exfiltrated credentials including GitHub PATs and cloud API keys (AWS, GCP, Azure). The incident poses high risk to frontend JavaScript applications (notably payment/crypto flows); mitigations advised include pinning and blocking malicious dependency versions, rotating tokens, enforcing phishing-resistant MFA, auditing CI/CD, enabling secret scanning, and blocking known exfiltration domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.