Supply chain, DevOps

Popular packages impacted by largest npm supply chain intrusion yet

(Credit: Araki Illustrations – stock.adobe.com)

Malware has been deployed on 18 widely used developer utilities with over 2.6 billion weekly downloads as part of the largest npm supply chain attack so far, SiliconANGLE reports.

Threat actors used a counterfeit npm support email and stolen credentials to infiltrate the libraries' maintainer account before compromising the packages' index.js files with illicit code that tracked multiple browser application programming interfaces and wallet interfaces to take over cryptocurrency transactions, according to an analysis from Aikido Security.

Cybersecurity experts have emphasized the severity of the attack involving malware injections on the chalk, debug, and ansi-styles utilities, each of which has been downloaded at least 300 million times per week.

"The compromise of npm packages with over 2.6 billion weekly downloads highlights just how devastating upstream attacks can be when they exploit the foundational trust built into open-source ecosystems," said SOCRadar Cyber Intelligence Chief Information Security Officer Ensar Seker.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds