logo

What AWS Security learned from responding to recent npm supply chain threat campaigns

ID: 5524f91b-a186-5ad6-a3cf-8dfa72313606

STIX ID: report--5524f91b-a186-5ad6-a3cf-8dfa72313606

Feed Name: AWS Security Blog

Threat Score
85/100

Date Published: 2025-12-15

Date Updated: 2026-04-27

Author: Nikki Pahliney

...
...

AWS Security describes its incident response to multiple large-scale npm supply-chain campaigns — including the Nx compromise, the Shai-Hulud worm, and a token‑farming operation that yielded ~150,000 malicious packages — detailing how the malware harvested npm/GitHub/cloud tokens and propagated via postinstall scripts and malicious workflows, the rapid detection and community coordination (OpenSSF) performed, and recommended defensive measures such as continuous monitoring, layered protections, dependency inventory, and coordinated reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.