logo

NPM Supply Chain: A Critical Threat to Cloud-Native

ID: ea34767e-badb-5689-adca-5ffec8416f48

STIX ID: report--ea34767e-badb-5689-adca-5ffec8416f48

Feed Name: Aqua Security Blog

Threat Score
90/100

Date Published: 2025-09-09

Date Updated: 2026-04-26

...
...

**Executive summary:** A software supply-chain attack compromised an npm maintainer via a phishing domain, enabling publication of tainted versions of 18 popular packages (collectively ~2.6 billion weekly downloads) that injected browser-based malware to hijack crypto/Web3 transactions; a security firm detected the malicious updates and the maintainer removed affected versions within hours, and the report advocates SBOMs, dynamic threat analysis, and runtime protections to mitigate such risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.