• News/
  • https://www.zdnet.com/article/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late/

5 ways to spot software supply chain attacks and stop worms - before it's too late

ZDNet
·
Steven Vaughan-Nichols
·
Published Sep 19, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. For those of you who aren't Dune fans, Shai-Hulud are the giant sandworms of the desert planet Arrakis. You do not want to get in their way. Now, it's also the name of a self-replicating worm that compromised at least 180 npm packages, and perhaps as many as 500 of them. This is a major security crisis for anyone who programs in JavaScript and the JavaScript runtime environment Node.js. JavaScript, by the way, is one of the most popular programming languages. This supply chain attack hits pretty much all JavaScript developers. Also: This 2FA phishing scam pwned a developer - and endangered billions of npm downloads That's because Node Package Manager (npm) is JavaScript's default package manager and software registry. It enables developers to install, manage, and share packages -- prebuilt pieces of reusable code called modules -- that their JavaScript or Node.js projects depend on. Npm is the largest such open-source package library. Essentially, everyone who uses JavaScript uses it. Npm also has a horrible security track record. Month after month, year after year, hackers have successfully inserted malicious code into npm modules. This, in turn, means that corrupted code is automatically introduced into JavaScript-based programs used by end users. The most recent example of this was a week ago, when a phishing attack compromised 18 packages that were downloaded two billion times a week. This week's attack is much worse. ...

Read full article

Affected Software

1 affected component
npm Node Package Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203