logo

Learnings from recent npm supply chain compromises

ID: 155f3991-ba37-560c-81f6-7ab25808c8c0

STIX ID: report--155f3991-ba37-560c-81f6-7ab25808c8c0

Feed Name: Datadog Security Labs

Threat Score
90/100

Date Published: 2025-10-30

Date Updated: 2026-04-27

...
...

This report details a series of large-scale npm supply-chain attacks (s1ngularity, a Qix/debug/chalk compromise, Shai-Hulud, and GhostActions) in which attackers exploited GitHub Actions (pull_request_target), phishing, and unrotated tokens to publish malicious package versions containing credential-harvesting and crypto-stealing code, exfiltrate thousands of secrets, and convert private repositories to public; it emphasizes the scale and impact of CI/CD and token-based weaknesses and recommends hardening GitHub Actions, rotating credentials, enabling MFA, using SCA/SAST tools, and deploying defensive tools like GuardDog and Supply-Chain Firewall.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.