Phishing Attack Leads to Malware in 5 npm Packages After Token Theft

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cybersecurity Alert: Supply Chain Attacks Targeting npm Packages

Overview of Recent Attacks

Cybersecurity experts have issued a critical warning about a recent supply chain attack affecting widely used npm packages. This incident involves a sophisticated phishing campaign aimed at stealing npm tokens from project maintainers. By capturing these tokens, attackers are able to publish malicious versions of packages directly to the npm registry without any authorization from the original maintainers.

Details of the Attack

The specific npm packages targeted in this attack include several popular libraries. According to findings from security firm Socket, the compromised packages and their rogue versions are as follows:

  • eslint-config-prettier: Versions 8.10.1, 9.1.1, 10.1.6, and 10.1.7
  • eslint-plugin-prettier: Versions 4.2.2 and 4.2.3
  • synckit: Version 0.11.9
  • @pkgr/core: Version 0.2.8
  • napi-postinstall: Version 0.3.1

Once these malicious versions were published, they attempted to execute a Dynamic-link Library (DLL) on Windows systems, which potentially allows for remote code execution.

Phishing Tactics Employed

This attack follows a detailed phishing strategy, where attackers sent out emails impersonating npm to deceive project maintainers into clicking on a fraudulent link. The tricky URL—typosquatted as "npnjs[.]com" instead of the legitimate "npmjs[.]com"—was designed to harvest user credentials.

The emails, often featuring the subject "Please verify your email address," were crafted to appear as if they came from the official npm support team. Victims were directed to a counterfeit landing page that mimicked the legitimate npm login page, thus capturing their login information.

Recommendations for Developers

To mitigate the risks associated with this threat, developers who use the affected packages are strongly advised to review the versions installed and revert to safer, unaffected versions. Additionally, project maintainers should enable two-factor authentication for their accounts and utilize scoped tokens rather than passwords for package publishing. This practice can greatly enhance the security of their accounts against similar phishing attempts in the future.

Security researchers at Socket emphasize that this incident underscores how quickly phishing attacks can escalate into widespread dangers affecting entire ecosystems.

Protestware Campaigns on npm

Interestingly, this alert coincides with another ongoing trend involving protestware on the npm platform. Recently, 28 new packages containing protestware elements were discovered. These packages are designed to disable mouse interactions on websites with Russian or Belarusian domains and to play the Ukrainian national anthem repetitively.

However, the effectiveness of this protestware is limited. It only activates if the site visitor’s browser settings are set to Russian and if they revisit the same webpage, suggesting a targeted approach to influence repeat visitors. This activity expands upon concerns that were first raised last month.

Arch Linux Responds to Malware Threats

In related news, the Arch Linux team has announced the removal of three malicious packages from the Arch User Repository (AUR). These packages were found to have an underlying functionality that allowed the installation of a Remote Access Trojan, known as Chaos RAT, from a now-deleted GitHub repository. The affected packages include:

  • librewolf-fix-bin
  • firefox-patch-bin
  • zen-browser-patched-bin

These packages, uploaded by a user identified as "danikpapas" on July 16, 2025, raised significant security concerns. The Arch maintainers strongly urge users who may have installed these packages to uninstall them immediately and take necessary precautions to ensure their systems have not been compromised.

Conclusion

The rising incidence of supply chain attacks and malicious packages calls for increased vigilance across the developer community. By following best practices for security, and staying informed about the latest threats, developers can better protect themselves and their projects from evolving risks in the digital landscape.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CWME_REVIEW_REQUIRED

CWME_REVIEW_REQUIRED Explore more technology and cybersecurity reporting from Cyber Warriors Middle East.

CISA Unveils Plan to Enhance Quality of Common Vulnerabilities and Exposures Program Amid Rising CVE Submissions

The Cybersecurity and Infrastructure Security Agency (CISA) has released a white paper outlining its strategy to enhance the Common Vulnerabilities and Exposures (CVE) program,...

Red Hat releases important kernel security update for RHEL 8.6 Advanced and Extended Support

Red Hat has announced a significant kernel security update for its Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission Critical Update Support and RHEL...

Syria seeks to transform Russian military bases into training centers

Syria is seeking to transform Russian military bases into training centers for its own armed forces, as part of a broader strategy to eliminate...