logo

Poisoned npm Packages Disguised as Utilities Aim for System Wipeout

ID: b9d196d0-f911-5bdd-8680-6f14fda938ca

STIX ID: report--b9d196d0-f911-5bdd-8680-6f14fda938ca

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-06-10

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers discovered two malicious npm packages (express-api-sync and system-health-sync-api) that embed backdoors—triggerable via HTTP endpoints and credentials—to delete application files and wipe systems. The packages, published from a single npm account, range from a simple destructive backdoor to a more sophisticated cross-platform, multi-endpoint wiper that performs reconnaissance and adapts commands by OS; both have been flagged for removal, and the case highlights an emerging destructive supply-chain threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.