logo

npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders

ID: b4884d14-0974-56c8-a4b3-00170ce9911a

STIX ID: report--b4884d14-0974-56c8-a4b3-00170ce9911a

Feed Name: Socket Blog

Threat Score
20/100

Date Published: 2026-06-09

Date Updated: 2026-06-11

Author: Sarah Gooding

...
...

npm unintentionally applied security-holder metadata (e.g., `0.0.1-security`, `0.0.1-security.0`) to multiple one-character packages and moved the `latest` dist-tag to those placeholders due to a tooling bug; older versions remained available, there is no public evidence of package compromise, npm has reverted the markings, and developers should check lockfiles (e.g., `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`) for the placeholder versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.