logo

Hackers Can Target Mailchimp Users By Exploiting a Dependency Confusion Bug

ID: 32159483-4e37-53e7-ac97-e5c9403f03ec

STIX ID: report--32159483-4e37-53e7-ac97-e5c9403f03ec

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2022-10-20

Date Updated: 2026-04-27

...
...

BeVigil and CloudSEK researchers discovered that Mailchimp's API documentation directs users to install unscoped npm packages (mailchimp-marketing and mailchimp_transactional) that were unclaimed on npmjs, enabling dependency confusion. The researchers published a claim for mailchimp-marketing, added a webhook, and observed significant usage (72,389 hits and roughly 500–1000 webhook triggers per week), demonstrating that an attacker could deliver remote code execution, malware, or ransomware; they recommend updating documentation to use scoped package names (e.g., @mailchimp/mailchimp_marketing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.