Poisoned npm Packages Disguised as Utilities Aim for System Wipeout
ID: b9d196d0-f911-5bdd-8680-6f14fda938ca
STIX ID: report--b9d196d0-f911-5bdd-8680-6f14fda938ca
Feed Name: Dark Reading
Date Published: 2025-06-10
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers discovered two malicious npm packages (express-api-sync and system-health-sync-api) that embed backdoors—triggerable via HTTP endpoints and credentials—to delete application files and wipe systems. The packages, published from a single npm account, range from a simple destructive backdoor to a more sophisticated cross-platform, multi-endpoint wiper that performs reconnaissance and adapts commands by OS; both have been flagged for removal, and the case highlights an emerging destructive supply-chain threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
