logo

Compromised npm package threatens developer projects

ID: b8cdfcb3-106c-50a1-864e-9cc78a9331ce

STIX ID: report--b8cdfcb3-106c-50a1-864e-9cc78a9331ce

Feed Name: ReversingLabs Blog

Threat Score
80/100

Date Published: 2025-08-14

Date Updated: 2026-04-29

Author: Karlo Zanki

...
...

ReversingLabs and Socket reported that on July 18 attackers successfully phished an npm package maintainer and published malicious versions of eslint-config-prettier (and other packages) whose postinstall scripts dropped a DLL containing the Scavenger RAT; automated dependency update tooling (e.g., Dependabot with automerge) caused the malware to be installed in CI/build workflows, resulting in at least 46 identified repository occurrences and the potential compromise of build machines and leaked GitHub tokens. The report details the attack vector, npm version-resolution considerations, propagation via automated updates, remediation actions taken, and recommendations to reduce supply-chain risk (vet automated merges, separate devDependencies, pause noncritical upgrades).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.