logo

Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond

ID: b1aae965-f64e-5db4-83c7-9491ce8b24e3

STIX ID: report--b1aae965-f64e-5db4-83c7-9491ce8b24e3

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2025-09-09

Date Updated: 2026-05-01

...
...

On 2025-09-08 a threat actor gained control of an npm maintainer account and published malicious releases of widely used packages (including debug and chalk and packages in the DuckDB ecosystem). The injected, obfuscated JavaScript, when served to end users, hooks fetch/XHR and wallet APIs (e.g., window.ethereum and Solana signing methods) to silently rewrite recipients/approvals and divert cryptocurrency transactions. The malicious versions were available for a short ~2-hour window but reached many cloud builds and bundles; the advisory lists affected versions, sample obfuscated code for detection, recommended mitigations (blocklist, cache/CI cleans, CDN invalidation, bundle scans, SRI), and steps for on-chain triage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.