• News/
  • https://www.bleepingcomputer.com/news/security/npm-package-is-with-28m-weekly-downloads-infected-devs-with-malware/

NPM package ‘is’ with 2.8M weekly downloads infected devs with malware

BleepingComputer
·
Bill Toulas
·
Published Jul 23, 2025
·
Updated

The popular NPM package 'is' has been compromised in a supply chain attack that injected backdoor malware, giving attackers full access to compromised devices. This occurred after maintainer accounts were hijacked via phishing, followed by unauthorized owner changes that went unnoticed for several hours, potentially compromising many developers who downloaded the new releases. The 'is' package is a lightweight JavaScript utility library that provides a wide variety of type checking and value validation functions. The software has over 2.8 million weekly downloads on the NPM package index. It is used extensively as a low-level utility dependency in development tools, testing libraries, build systems, and backend and CLI projects. On July 19, 2025, the package's primary maintainer, John Harband, announced that versions 3.3.1 through 5.0.0 contained malware and were removed roughly 6 hours after threat actors submitted them to npm.

This was the result of the same NPM supply chain attack that used the fake domain' npnjs[.]com' to snatch maintainer credentials and then publish laced versions of popular packages. Besides 'is,' the following packages were confirmed to be pushing malware, compromised in the same attack: Socket reports that 'is' contains a cross-platform JavaScript malware loader that opens a WebSocket-based backdoor, enabling remote code execution. "Once active, it queries Node's os module to collect the hostname, operating system, and CPU details, and captures all...

Read full article

Affected Software

2 affected components
npm is=3.3.1
npm is=5.0.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security breach involving the popular NPM package 'is' that was infected with malware.

2

What security implications are discussed?

The article highlights the risks of supply chain attacks, where compromised maintainer accounts can lead to widespread malware infection.

3

What products or software are affected?

The NPM package 'is', specifically versions 3.3.1 and 5.0.0, are affected by the malware infection.

4

How was the NPM package 'is' compromised?

The package was compromised through phishing attacks that hijacked maintainer accounts.

5

What type of malware was injected into the NPM package?

The injected malware was a backdoor that provided attackers full access to compromised devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203