Open source repositories are seeing a rash of supply-chain attacks

Open source repositories are seeing a rash of supply-chain attacks

In a troubling trend, the past week has witnessed a significant uptick in supply-chain attacks aimed at open source software housed in public repositories. These assaults have successfully compromised several developer accounts, leading to the distribution of harmful packages to unsuspecting users. The latest incident, as reported by cybersecurity firm Socket, involved malicious JavaScript code found on the npm repository. A total of 10 infected packages linked to the global talent agency Toptal were downloaded by around 5,000 users before the attack was identified and the packages removed. This incident marks the third supply-chain attack that Socket has detected on npm within just one week. The attackers gained access by breaching Toptal’s GitHub Organization and subsequently leveraged that access to upload malicious packages on npm. Researchers are still piecing together the exact mechanics of the attack, particularly the connection between the changes made in the GitHub repository and the package publications on npm. According to Socket, the npm package publishing likely occurred through GitHub Actions or stored npm tokens, which became vulnerable after the GitHub Organization was compromised. The integration between GitHub and npm in development workflows facilitates the publishing of npm packages once a GitHub organization is hijacked. Socket researchers noted that the attack could have stemmed from compromised GitHub access that allowed for both repository alterations and npm package publishing, or from distinct weaknesses that impacted both platforms separately. They emphasized that without further forensic analysis, deciphering the exact interplay and timeline of these events remains a complex challenge.

Sources : Ars Technica

Published On : Jul 25, 2025, 15:55

AI
Major $1.5 Billion Copyright Settlement Approved for Anthropic

Anthropic is set to disburse payments to a collective of authors and publishers following a significant $1.5 billion set...

TechCrunch | Jul 21, 2026, 24:40
Major $1.5 Billion Copyright Settlement Approved for Anthropic
Startups
Agility Robotics Shuns Hiring Wars, Focuses on Culture and Innovation

Agility Robotics has recently established a new base in Silicon Valley, aiming to attract top-tier engineers for its inn...

Business Insider | Jul 20, 2026, 21:45
Agility Robotics Shuns Hiring Wars, Focuses on Culture and Innovation
Startups
Navigating Market Turbulence: Cramer Urges Caution in Tech Investments

In a recent discussion, CNBC's Jim Cramer expressed concerns about the current state of the artificial intelligence mark...

CNBC | Jul 20, 2026, 22:35
Navigating Market Turbulence: Cramer Urges Caution in Tech Investments
Cybersecurity
Cybersecurity Alert: Millions of WordPress Sites at Risk from Exploited Vulnerabilities

Recent cybersecurity reports indicate that hackers are actively targeting websites that utilize outdated versions of the...

TechCrunch | Jul 20, 2026, 15:55
Cybersecurity Alert: Millions of WordPress Sites at Risk from Exploited Vulnerabilities
Mobile
X Launches Ground-Up Redesign of Android App for Enhanced User Experience

In a significant move for its users, X, led by Elon Musk, has unveiled a completely reimagined version of its Android ap...

Business Today | Jul 21, 2026, 05:25
X Launches Ground-Up Redesign of Android App for Enhanced User Experience
View All News