Open source repositories are seeing a rash of supply-chain attacks

Open source repositories are seeing a rash of supply-chain attacks

In a troubling trend, the past week has witnessed a significant uptick in supply-chain attacks aimed at open source software housed in public repositories. These assaults have successfully compromised several developer accounts, leading to the distribution of harmful packages to unsuspecting users. The latest incident, as reported by cybersecurity firm Socket, involved malicious JavaScript code found on the npm repository. A total of 10 infected packages linked to the global talent agency Toptal were downloaded by around 5,000 users before the attack was identified and the packages removed. This incident marks the third supply-chain attack that Socket has detected on npm within just one week. The attackers gained access by breaching Toptal’s GitHub Organization and subsequently leveraged that access to upload malicious packages on npm. Researchers are still piecing together the exact mechanics of the attack, particularly the connection between the changes made in the GitHub repository and the package publications on npm. According to Socket, the npm package publishing likely occurred through GitHub Actions or stored npm tokens, which became vulnerable after the GitHub Organization was compromised. The integration between GitHub and npm in development workflows facilitates the publishing of npm packages once a GitHub organization is hijacked. Socket researchers noted that the attack could have stemmed from compromised GitHub access that allowed for both repository alterations and npm package publishing, or from distinct weaknesses that impacted both platforms separately. They emphasized that without further forensic analysis, deciphering the exact interplay and timeline of these events remains a complex challenge.

Sources : Ars Technica

Published On : Jul 25, 2025, 15:55

AI
Is Apple Missing the AI Revolution? A Strategic Gamble or a Risky Move?

In a landscape where tech giants are rapidly embracing artificial intelligence, Apple seems to be taking a cautious appr...

CNBC | Feb 27, 2026, 15:25
Is Apple Missing the AI Revolution? A Strategic Gamble or a Risky Move?
Cybersecurity
CISA Shifts Leadership Amid Ongoing Turmoil and Staffing Challenges

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is facing significant challenges, prompting the agency ...

TechCrunch | Feb 27, 2026, 16:15
CISA Shifts Leadership Amid Ongoing Turmoil and Staffing Challenges
AI
Perplexity Unveils Revolutionary AI Tool for Enhanced User Experience

This week, subscribers of Perplexity will gain access to an innovative tool designed to streamline AI capabilities. Dubb...

TechCrunch | Feb 27, 2026, 17:10
Perplexity Unveils Revolutionary AI Tool for Enhanced User Experience
Startups
Final Chance to Snag Discounted Tickets for TechCrunch Disrupt 2026!

The countdown is on! As the clock approaches 11:59 p.m. PT tonight, the opportunity to purchase tickets for TechCrunch D...

TechCrunch | Feb 27, 2026, 15:05
Final Chance to Snag Discounted Tickets for TechCrunch Disrupt 2026!
Startups
Deepinder Goyal Makes Bold Move into Wearable Tech with $54M Investment

After stepping down as CEO of Zomato, Deepinder Goyal is back in the spotlight with a substantial $54 million investment...

TechCrunch | Feb 27, 2026, 15:05
Deepinder Goyal Makes Bold Move into Wearable Tech with $54M Investment
View All News