Software packages with more than 2 billion weekly downloads hit in supply-chain attack

Software packages with more than 2 billion weekly downloads hit in supply-chain attack

In a shocking breach, hackers have infiltrated open source software packages that collectively receive over 2 billion downloads each week, marking one of the largest supply-chain attacks in history. This alarming incident, which has impacted nearly two dozen packages on the npm repository, came to light following social media discussions on Monday. The breach was linked to Josh Junon, a maintainer of the compromised packages, who revealed that he had been deceived by a phishing email. The fraudulent message claimed that his npm account would be suspended unless he updated his two-factor authentication settings on a fake website. In a candid post, Junon, also known by his handle Qix, expressed regret over the incident, acknowledging his lapse in vigilance during a particularly stressful week. Seizing the opportunity from this account compromise, the attackers swiftly manipulated the situation. Within just one hour, they pushed updates to numerous open source packages that included malicious code designed to siphon cryptocurrency into wallets controlled by the attackers. This nefarious addition spanned over 280 lines of code and was engineered to monitor cryptocurrency transactions on infected systems, linking them to the attackers’ wallets. Among the 20 compromised packages were vital components of the JavaScript ecosystem, many of which are foundational and have extensive dependencies. These packages are not only widely utilized but also have numerous other npm packages reliant on them, amplifying the potential fallout of the attack. Security experts from Socket highlighted that the attack's impact is significantly magnified due to the high-profile nature of the projects involved, allowing the hackers to disseminate malicious versions of packages that are crucial for countless applications, libraries, and frameworks. With the breadth and selection of affected packages, the incident appears meticulously orchestrated, aimed at maximizing disruption across the software ecosystem.

Sources : Ars Technica

Published On : Sep 09, 2025, 24:40

Cybersecurity
Government Takes Action Against Meta Over Alarming Child Abuse Ads on Instagram

In a significant move, the Indian government has issued a formal notice to Meta regarding the disturbing presence of Chi...

Business Today | Jul 05, 2026, 08:00
Government Takes Action Against Meta Over Alarming Child Abuse Ads on Instagram
AI
What If the Founding Fathers Had AI? Google's New Ad Sparks Debate

In a creative twist, Google has released a commercial that envisions how the Founding Fathers might have utilized modern...

TechCrunch | Jul 04, 2026, 21:15
What If the Founding Fathers Had AI? Google's New Ad Sparks Debate
Gadgets
Transform Your Workspace: 5 Must-Have Desk Gadgets for Enhanced Productivity

In today's fast-paced work environment, where many of us spend countless hours at our desks, optimizing our workspace is...

TechCrunch | Jul 05, 2026, 15:15
Transform Your Workspace: 5 Must-Have Desk Gadgets for Enhanced Productivity
AI
How AI Transformed a Lawyer's Workflow: A Game Changer in Legal Practice

Zack Shapiro, a corporate attorney and managing partner of the innovative AI-focused law firm Rains, has experienced a r...

Business Insider | Jul 05, 2026, 09:55
How AI Transformed a Lawyer's Workflow: A Game Changer in Legal Practice
Gadgets
Top 5 Smartphones Under ₹25,000: Must-Have Picks From Amazon and Flipkart Sales

As the Amazon and Flipkart sales unfold, a plethora of impressive smartphones are available for under ₹25,000. This pric...

Business Today | Jul 04, 2026, 05:10
Top 5 Smartphones Under ₹25,000: Must-Have Picks From Amazon and Flipkart Sales
View All News