• News/
  • https://www.bleepingcomputer.com/news/security/hackers-left-empty-handed-after-massive-npm-supply-chain-attack/

Hackers left empty-handed after massive NPM supply-chain attack

BleepingComputer
·
Bill Toulas
·
Published Sep 10, 2025
·
Updated

The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but the attacker made little profit off it. The attack occurred earlier this week after maintainer Josh Junon (qix) fell for a password reset phishing lure and compromised multiple highly popular NPM packages, among them chalk and degub-js, that cumulatively have more than 2.6 billion weekly downloads. After gaining access to Junon’s account, the attackers pushed malicious updates with a malicious module that stole cryptocurrency by redirecting transactions to the threat actor. The open-source software community quickly discovered the attack, and all the malicious packages were removed within two hours. According to researchers at cloud security company Wiz, one or more of the compromised packages, which are fundamental building blocks for nearly any JavaScript/Node project, were used in 99% of cloud environments. During the two-hour window they were available for download, the compromised packages were pulled by roughly 10% of cloud environments. “During the short 2-hour timeframe in which the malicious versions were available on npm, the malicious code successfully reached 1 in 10 cloud environments,” explained Wiz. “This serves to demonstrate how fast malicious code can propagate in supply chain attacks like this one.” The 10% figure is based on Wiz’s visibility into customer cloud environments, as well as public sources. While it may not be a repres...

Read full article

Affected Software

2 affected components
npm chalk
npm debug-js

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a significant NPM supply-chain attack that compromised a large number of cloud environments.

2

What security implications are discussed in the article?

The article highlights the vulnerabilities in the NPM ecosystem and the risks associated with phishing attacks targeting software maintainers.

3

What products or software are affected by this attack?

The attack primarily affected npm packages such as 'chalk' and 'debug-js'.

4

How many cloud environments were impacted by the NPM attack?

The attack impacted roughly 10% of all cloud environments globally.

5

What were the attackers' outcomes from the NPM supply-chain attack?

Despite the scale of the attack, the hackers made little profit from their efforts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203