fsevents supply chain attack (Incident)
ID: 4dc82424-545c-5658-a182-b8bd8b3ec371
STIX ID: report--4dc82424-545c-5658-a182-b8bd8b3ec371
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2023-04-27
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
The fsevents npm package previously fetched remote binaries from a public S3 bucket which became dangling and was hijacked in April 2023; the attacker replaced the binaries with information-stealing malware as a proof-of-concept. AWS reclaimed the bucket and fsevents no longer downloads those binaries as of v1.2.11, but installations existing before the April 2023 hijack may still be infected and should be audited or remediated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
