Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond
ID: b1aae965-f64e-5db4-83c7-9491ce8b24e3
STIX ID: report--b1aae965-f64e-5db4-83c7-9491ce8b24e3
Feed Name: Wiz Blog
On 2025-09-08 a threat actor gained control of an npm maintainer account and published malicious releases of widely used packages (including debug and chalk and packages in the DuckDB ecosystem). The injected, obfuscated JavaScript, when served to end users, hooks fetch/XHR and wallet APIs (e.g., window.ethereum and Solana signing methods) to silently rewrite recipients/approvals and divert cryptocurrency transactions. The malicious versions were available for a short ~2-hour window but reached many cloud builds and bundles; the advisory lists affected versions, sample obfuscated code for detection, recommended mitigations (blocklist, cache/CI cleans, CDN invalidation, bundle scans, SRI), and steps for on-chain triage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
