logo

"Yep, I got pwned. Sorry everyone, very embarrassing."

ID: ac6ff6c8-660e-57d8-bb83-d19481c3fdc9

STIX ID: report--ac6ff6c8-660e-57d8-bb83-d19481c3fdc9

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2025-09-10

Date Updated: 2026-04-28

Author: Martin Kraemer

...
...

An open-source maintainer account (qix) was social-engineered and used to push malware into popular NPM packages (e.g., chalk, debug, ansi-styles). The payload aimed to intercept browser network calls and wallet transactions (including MetaMask) to replace legitimate crypto addresses with attacker wallets across multiple blockchains; CI errors limited the live window to roughly two hours. The incident highlights severe supply-chain risk in open-source ecosystems and recommends stronger CI/CD safeguards, phishing-resistant MFA, trusted publishing, and monitoring of package changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.