logo

Supply Chain Attack on npm Packages via Maintainer Phishing (Campaign)

ID: 1aba0867-64e6-54ce-bccf-984207b97b15

STIX ID: report--1aba0867-64e6-54ce-bccf-984207b97b15

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2025-07-20

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A phishing attack against a popular npm maintainer resulted in token theft and the publication of malicious package versions across multiple npm packages (including eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, is, got-fetch) and a PyPI package (num2words). The malicious packages used postinstall scripts to deploy Windows malware (Scavenger), executing malicious DLLs via rundll32 under a disguised function to evade most antivirus engines; the incident represents a cross-ecosystem supply-chain compromise with active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.