logo

Detecting the NPM Supply Chain Compromise Before It Spread

ID: 6834bad3-ea0c-54ee-9cb8-c7c58c21ee6d

STIX ID: report--6834bad3-ea0c-54ee-9cb8-c7c58c21ee6d

Feed Name: Group-IB Blog

Threat Score
88/100

Date Published: 2025-10-31

Date Updated: 2026-04-28

...
...

Group-IB describes a simulated NPM supply-chain compromise in which a phishing campaign impersonating NPM Support led to the takeover of a developer account (qix) and modification of 20 popular packages with a JavaScript clipper that replaced cryptocurrency wallet addresses (targeting BTC, ETH, SOL, TRX, LTC, BCH); the report lists IOCs (domains, URLs, IP), details phishing tactics, and explains how Business Email Protection detects such attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.