logo

NPM command confusion 

ID: f1e98d48-ff0c-519e-976a-5ea591da4eae

STIX ID: report--f1e98d48-ff0c-519e-976a-5ea591da4eae

Feed Name: Checkmarx Zero

Threat Score
50/100

Date Published: 2025-01-14

Date Updated: 2026-04-27

Author: Eugene Rojavski

...
...

The report describes an npm CLI alias confusion where the newly added "npm add" alias for "npm install" can be mistyped as "npm add user", causing developers to unintentionally install a benign-but-widely-downloaded "user" package instead of using "npm adduser" to log in; with millions of downloads and thousands of dependents, the package represents a potential supply-chain risk if future versions include malicious code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.