logo

CrowdStrike Falcon Prevents Supply Chain Attack Involving Compromised NPM Packages

ID: e52f2378-46b7-5f06-b19a-bdd02391a5c1

STIX ID: report--e52f2378-46b7-5f06-b19a-bdd02391a5c1

Feed Name: Crowdstrike Blog

Threat Score
80/100

Date Published: 2025-07-23

Date Updated: 2026-04-27

Author: Veronica Tecan

...
...

On July 18, 2025, an attacker leveraged credential phishing against an NPM package maintainer to publish malicious versions of five widely used packages (including eslint-config-prettier). The compromised packages ran an install script that launched a Scavenger DLL (node-gyp.dll) via rundll32.exe; the DLL exfiltrated .npmrc authentication tokens and wrote a second-stage infostealer that harvested browser data. A CVE was assigned to the incident, affected packages were deprecated and republished cleanly, and CrowdStrike Falcon detections reportedly blocked the malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.