• News/
  • https://www.bleepingcomputer.com/news/security/hackers-hijack-npm-packages-with-2-billion-weekly-downloads-in-supply-chain-attack/

Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 8, 2025
·
Updated

In a supply chain attack, attackers injected malware into NPM packages with over 2.6 billion weekly downloads after compromising a maintainer's account in a phishing attack. Josh Junon (qix), the package maintainer whose accounts were hijacked in this supply-chain attack, confirmed the incident earlier today, stating that he was aware of the compromise and adding that the phishing email came from support [at] npmjs [dot] help, a domain that hosts a website impersonating the legitimate npmjs.com domain. In the emails, the attackers threatened that the targeted maintainers' accounts would be locked on September 10th, 2025, as a scare tactic to get them to click on the link redirecting them to the phishing sites. "As part of our ongoing commitment to account security, we are requesting that all users update their Two-Factor Authentication (2FA) credentials. Our records indicate that it has been over 12 months since your last 2FA update," the phishing email reads. "To maintain the security and integrity of your account, we kindly ask that you complete this update at your earliest convenience. Please note that accounts with outdated 2FA credentials will be temporarily locked starting September 10, 2025, to prevent unauthorized access." The attackers targeted other package maintainers and developers using the same email, according to reports from those who received the phishing message. BleepingComputer found that the npmjs[.]help page also includes a login form that will exfiltra...

Read full article

Affected Software

1 affected component
npm package
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a supply chain attack where hackers hijacked NPM packages that generate 2 billion weekly downloads.

2

What security implications are discussed in the article?

The article highlights the risks of supply chain attacks and the potential for malware distribution through compromised software packages.

3

What products or software are affected by this security incident?

The affected products are NPM packages that were compromised as part of the attack.

4

How did the attackers gain access to the NPM packages?

Attackers compromised a maintainer's account through a phishing attack to inject malware into the packages.

5

What is the scale of the downloads for the affected NPM packages?

The affected NPM packages had over 2.6 billion weekly downloads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203