Open source repositories are seeing a rash of supply-chain attacks

Open source repositories are seeing a rash of supply-chain attacks

In a troubling trend, the past week has witnessed a significant uptick in supply-chain attacks aimed at open source software housed in public repositories. These assaults have successfully compromised several developer accounts, leading to the distribution of harmful packages to unsuspecting users. The latest incident, as reported by cybersecurity firm Socket, involved malicious JavaScript code found on the npm repository. A total of 10 infected packages linked to the global talent agency Toptal were downloaded by around 5,000 users before the attack was identified and the packages removed. This incident marks the third supply-chain attack that Socket has detected on npm within just one week. The attackers gained access by breaching Toptal’s GitHub Organization and subsequently leveraged that access to upload malicious packages on npm. Researchers are still piecing together the exact mechanics of the attack, particularly the connection between the changes made in the GitHub repository and the package publications on npm. According to Socket, the npm package publishing likely occurred through GitHub Actions or stored npm tokens, which became vulnerable after the GitHub Organization was compromised. The integration between GitHub and npm in development workflows facilitates the publishing of npm packages once a GitHub organization is hijacked. Socket researchers noted that the attack could have stemmed from compromised GitHub access that allowed for both repository alterations and npm package publishing, or from distinct weaknesses that impacted both platforms separately. They emphasized that without further forensic analysis, deciphering the exact interplay and timeline of these events remains a complex challenge.

Sources : Ars Technica

Published On : Jul 25, 2025, 15:55

Startups
Last Chance: Secure Your Spot at TechCrunch Disrupt 2026 with Early Bird Discounts

Time is running out to grab your ticket for TechCrunch Disrupt 2026 at a discounted rate. With just three days remaining...

TechCrunch | May 27, 2026, 14:35
Last Chance: Secure Your Spot at TechCrunch Disrupt 2026 with Early Bird Discounts
Streaming
Spotify Unveils New Feature for Sharing Podcast Highlights

Spotify is set to enhance the way listeners engage with podcasts through its latest feature, Podcast Clips, which launch...

TechCrunch | May 27, 2026, 14:35
Spotify Unveils New Feature for Sharing Podcast Highlights
AI
The Enduring Human Touch: Why AI Hasn't Fully Taken Over Jobs Yet

In an era where artificial intelligence (AI) was expected to revolutionize the job market, many roles remain resilient a...

Business Insider | May 27, 2026, 15:55
The Enduring Human Touch: Why AI Hasn't Fully Taken Over Jobs Yet
AI
YouTube Enhances AI Video Labeling for Greater Transparency

YouTube is stepping up its efforts to clarify the origins of videos generated by artificial intelligence. As AI content ...

Ars Technica | May 27, 2026, 17:40
YouTube Enhances AI Video Labeling for Greater Transparency
Gadgets
Govee Issues Apology After Inappropriate Marketing Image Surfaces

Govee, a prominent manufacturer of smart lighting solutions, has issued an apology following the appearance of a disturb...

Ars Technica | May 27, 2026, 17:05
Govee Issues Apology After Inappropriate Marketing Image Surfaces
View All News