logo

Popular npm linter packages hijacked via phishing to drop malware

ID: 8d29ebee-c47c-504c-bb2c-4f6d5e59cc91

STIX ID: report--8d29ebee-c47c-504c-bb2c-4f6d5e59cc91

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-07-19

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

Popular npm packages (notably eslint-config-prettier and related libraries) were hijacked after a maintainer fell for a phishing email; attackers used stolen npm credentials to publish malicious package versions that include a postinstall script which runs a trojan DLL via rundll32 on Windows. The report lists specific affected package versions to avoid, notes low detection on VirusTotal for the bundled DLL, and recommends checking lockfiles, CI/build artifacts, and rotating secrets as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.