In a supply chain attack, attackers injected malware into NPM packages with over 2.6 billion weekly downloads after compromising a maintainer's account in a phishing attack. Josh Junon (qix), the package maintainer whose accounts were hijacked in this supply-chain attack, confirmed the incident earlier today, stating that he was aware of the compromise and adding that the phishing email came from support [at] npmjs [dot] help, a domain that hosts a website impersonating the legitimate npmjs.com domain. In the emails, the attackers threatened that the targeted maintainers' accounts would be locked on September 10th, 2025, as a scare tactic to get them to click on the link redirecting them to the phishing sites. "As part of our ongoing commitment to account security, we are requesting that all users update their Two-Factor Authentication (2FA) credentials. Our records indicate that it has been over 12 months since your last 2FA update," the phishing email reads. "To maintain the security and integrity of your account, we kindly ask that you complete this update at your earliest convenience. Please note that accounts with outdated 2FA credentials will be temporarily locked starting September 10, 2025, to prevent unauthorized access." The attackers targeted other package maintainers and developers using the same email, according to reports from those who received the phishing message. BleepingComputer found that the npmjs[.]help page also includes a login form that will exfiltra...
Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack
BleepingComputer
·Sergiu Gatlan
·Published Sep 8, 2025
·Updated
Affected Software
1 affected component
npm package
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a supply chain attack where hackers hijacked NPM packages that generate 2 billion weekly downloads.
2
What security implications are discussed in the article?
The article highlights the risks of supply chain attacks and the potential for malware distribution through compromised software packages.
3
What products or software are affected by this security incident?
The affected products are NPM packages that were compromised as part of the attack.
4
How did the attackers gain access to the NPM packages?
Attackers compromised a maintainer's account through a phishing attack to inject malware into the packages.
5
What is the scale of the downloads for the affected NPM packages?
The affected NPM packages had over 2.6 billion weekly downloads.