logo

NPM Flaws Let Attackers Target Packages for Account Takeover

ID: 6a5f3f18-69a3-5bae-872d-5055483b0f06

STIX ID: report--6a5f3f18-69a3-5bae-872d-5055483b0f06

Feed Name: Aqua Security Blog

Threat Score
65/100

Date Published: 2022-04-05

Date Updated: 2026-04-26

...
...

Team Nautilus discovered and responsibly disclosed two npm information-disclosure flaws that allowed unauthenticated enumeration of maintainers' 2FA status and whether organizations enforced 2FA; using these findings and leaked-password data they measured supply-chain exposure and found substantial risk (32% of top-35 packages and 72% of devDependencies), demonstrating how compromised dependency maintainers could enable account takeovers and downstream malicious package updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.