Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html
ONE SENTENCE SUMMARY:
A phishing attack on a maintainer of npm packages led to a software supply chain attack affecting 20 popular packages.
MAIN POINTS:
- Maintainer’s account compromised via phishing email mimicking npm support.
- Attack targeted Josh Junon, co-maintainer of several npm packages.
- 20 npm packages affected; over 2 billion weekly downloads.
- Malware intercepts cryptocurrency transactions, alters destination wallet.
- Payload acts as a browser-based interceptor hijacking network traffic.
- Attack exploits trust in npm and PyPI package ecosystems.
- Techniques include typosquatting and exploiting AI-hallucinated dependencies.
- 14 of 23 crypto-related attacks in 2024 targeted npm.
- Targeting developers is strategic for reaching wide audiences.
- Package takeovers commonly used by advanced persistent threat groups.
TAKEAWAYS:
- Vigilance and security in CI/CD pipelines are crucial.
- Increasing attacks on software supply chain platforms like npm.
- Popular open source packages remain high-value targets.
- Developers need awareness of phishing and security practices.
- Strengthening account security and monitoring is essential.