"Yep, I got pwned. Sorry everyone, very embarrassing."
ID: ac6ff6c8-660e-57d8-bb83-d19481c3fdc9
STIX ID: report--ac6ff6c8-660e-57d8-bb83-d19481c3fdc9
Feed Name: KnowBe4 Blog
An open-source maintainer account (qix) was social-engineered and used to push malware into popular NPM packages (e.g., chalk, debug, ansi-styles). The payload aimed to intercept browser network calls and wallet transactions (including MetaMask) to replace legitimate crypto addresses with attacker wallets across multiple blockchains; CI errors limited the live window to roughly two hours. The incident highlights severe supply-chain risk in open-source ecosystems and recommends stronger CI/CD safeguards, phishing-resistant MFA, trusted publishing, and monitoring of package changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
