Massive Attack on npm: 18 Popular Packages Infected

September 10, 2025  20:19

Aikido Security Ltd. reported the largest incident in the history of npm, the largest repository of JavaScript libraries. Hackers injected malicious code into 18 packages, collectively downloaded over 2.6 billion times per week, according to SiliconANGLE.

Aikido stated that the attackers gained access to a maintainer's account through phishing, sending an email from a fake npm support service demanding an update to two-factor authentication. After hijacking the account, the attackers added code designed to intercept cryptocurrency transactions and redirect funds to their wallets.

The incident was detected just five minutes after the infected packages were published, and the information became public within an hour. This quick response limited the damage, though the infection persisted for about two and a half hours. Key libraries such as chalk, debug, and ansi-styles, which are downloaded hundreds of millions of times weekly and form the backbone of the JavaScript ecosystem, were at risk.

Experts call the event a “turning point” for software supply chain security. They note that the attackers didn’t need to breach servers or bypass sophisticated defenses—just compromising a single account was enough. This attack highlights the vulnerability of global open-source projects, on which millions of developers worldwide depend.

Follow NEWS.am Tech on Facebook and Twitter