Qix npm package supply chain compromise (Incident)
ID: 3fa7e8ca-bd06-5a13-acae-988daae44e03
STIX ID: report--3fa7e8ca-bd06-5a13-acae-988daae44e03
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-09-08
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
On 8–9 September 2025, the npm packages maintained by developer “Qix” were compromised and malicious versions of at least 18 popular packages (including [email protected] and [email protected]) were published; the injected browser code can silently redirect crypto transactions to attacker-controlled addresses. The maintainer acknowledged the compromise and began remediation, and additional affected packages were later reported by JFrog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
