logo

When Vigilance Causes an Outage: The NPM Stylus Package Outage

ID: 0ab16662-3afe-56ff-9790-c31bb854ebcd

STIX ID: report--0ab16662-3afe-56ff-9790-c31bb854ebcd

Feed Name: Checkmarx Zero

Threat Score
10/100

Date Published: 2025-07-29

Date Updated: 2026-04-27

Author: Rom Gotshal

...
...

In July 2025 the popular NPM package 'stylus' was mistakenly marked as malware following activity from a maintainer account, prompting NPM to place a security-holding version and causing roughly a 12-hour outage that broke builds for organizations relying on direct NPM installs; subsequent investigation found no malicious code in stylus and the incident is used to highlight lessons about private package caches, skilled AppSec response, and careful malware reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.