20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack

Following a phishing assault that hacked a maintainer’s account, a software supply chain attack has compromised multiple npm packages.

The assault was directed at Josh Junon (also known as Qix), who was urged to update their two-factor authentication (2FA) credentials by clicking on an embedded link in an email that imitated npm (“support@npmjs[.]help”) by September 10, 2025.

The co-maintainer allegedly entered their username, password, and two-factor authentication (2FA) token on the phishing page. The token was then allegedly taken, most likely through an adversary-in-the-middle (AitM) attack, and used to publish the rogue version to the npm registry.

It has been confirmed that the following 20 packages, which together receive over 2 billion downloads every week, are impacted by the incident read more about 20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *