Open source repositories are seeing a rash of supply-chain attacks

Open source repositories are seeing a rash of supply-chain attacks

In a troubling trend, the past week has witnessed a significant uptick in supply-chain attacks aimed at open source software housed in public repositories. These assaults have successfully compromised several developer accounts, leading to the distribution of harmful packages to unsuspecting users. The latest incident, as reported by cybersecurity firm Socket, involved malicious JavaScript code found on the npm repository. A total of 10 infected packages linked to the global talent agency Toptal were downloaded by around 5,000 users before the attack was identified and the packages removed. This incident marks the third supply-chain attack that Socket has detected on npm within just one week. The attackers gained access by breaching Toptal’s GitHub Organization and subsequently leveraged that access to upload malicious packages on npm. Researchers are still piecing together the exact mechanics of the attack, particularly the connection between the changes made in the GitHub repository and the package publications on npm. According to Socket, the npm package publishing likely occurred through GitHub Actions or stored npm tokens, which became vulnerable after the GitHub Organization was compromised. The integration between GitHub and npm in development workflows facilitates the publishing of npm packages once a GitHub organization is hijacked. Socket researchers noted that the attack could have stemmed from compromised GitHub access that allowed for both repository alterations and npm package publishing, or from distinct weaknesses that impacted both platforms separately. They emphasized that without further forensic analysis, deciphering the exact interplay and timeline of these events remains a complex challenge.

Sources : Ars Technica

Published On : Jul 25, 2025, 15:55

AI
OpenAI Enhances Shopping Features in ChatGPT After Instant Checkout Setback

OpenAI is introducing a revamped shopping experience within ChatGPT, aiming to simplify how users discover and compare p...

CNBC | Mar 24, 2026, 17:45
OpenAI Enhances Shopping Features in ChatGPT After Instant Checkout Setback
Automotive
Google Aims to Expand Android Automotive's Role in Your Vehicle

For over a decade, Android has been gradually integrating into the automotive sector, beginning with the introduction of...

Ars Technica | Mar 24, 2026, 18:30
Google Aims to Expand Android Automotive's Role in Your Vehicle
AI
Court Battle Brewing: Anthropic Challenges Pentagon's AI Blacklisting

Anthropic has taken its fight to a federal court in San Francisco, seeking an urgent injunction to halt the Pentagon's r...

CNBC | Mar 24, 2026, 16:00
Court Battle Brewing: Anthropic Challenges Pentagon's AI Blacklisting
AI
Anthropic's Claude Code: AI Now Navigates Your Desktop for You

Anthropic has stepped into the competitive arena of AI agents capable of taking over desktop tasks on your computer. The...

Ars Technica | Mar 24, 2026, 15:50
Anthropic's Claude Code: AI Now Navigates Your Desktop for You
Gadgets
Apple Maps to Introduce Ads This Summer Amid Privacy Assurances

Apple has announced an upcoming change to its Maps application, revealing that advertisements will start appearing for u...

Ars Technica | Mar 24, 2026, 18:05
Apple Maps to Introduce Ads This Summer Amid Privacy Assurances
View All News