logo

duckdb npm packages compromised

ID: 213d0cff-3e13-56bc-80eb-bd5ca746e202

STIX ID: report--213d0cff-3e13-56bc-80eb-bd5ca746e202

Feed Name: Aikido Security's Blog

Threat Score
70/100

Date Published: 2025-09-09

Date Updated: 2026-07-24

...
...

Overnight on September 9th, multiple npm packages (including duckdb and a wasm build) were observed with new malicious releases (versions 1.3.3 and 1.29.2) containing a payload that attempts to drain cryptocurrency wallets; the incident appears to be a supply-chain compromise likely achieved via phishing, and the vendor has deprecated the releases and issued an advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.