Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: npm (45 articles)Clear

Malicious npm package impersonates Twilio bug bounty probe to exfiltrate developer credentials

ReversingLabs detailed a malicious npm package, tw-pkgprobe-7731, that masquerades as an authorized Twilio bug-bounty research probe while harvesting developer data. Uploaded in mid-August by an account that no longer exists, it shipped eleven versions within about 45 minutes. Comments inside describe it as an authorized HackerOne probe that runs only inside Twilio's serverless sandbox and takes no destructive action. On execution it first checks for a Twilio developer environment and exits otherwise, then collects environment variables plus system details like mounts and temporary folders and exfiltrates them through a webhook. Later versions specifically target developers using Twilio APIs by searching for folders tied to particular Twilio account identifiers, sharpening the credential theft.

Check
Block and audit for tw-pkgprobe-7731 across developer and build environments, then rotate Twilio credentials and API keys exposed on any affected machine.
Affected
Developers integrating Twilio who installed the package inside a matching environment had environment variables and account-linked configuration harvested and sent to an attacker webhook.
Fix
Pin and vet npm dependencies, alert on packages that fingerprint the environment before acting, and restrict outbound webhooks from build and developer hosts.

Malicious npm package hides loader in runtime method to bypass install script controls

Checkmarx found an ongoing npm campaign built around indexed-btree, a package impersonating the popular sorted-btree library that has amassed two million weekly downloads. Instead of using preinstall or postinstall scripts, the malware hides its loader inside the BTree.prototype.set method that applications call constantly, so it executes at runtime rather than install time. This sidesteps the npm approval gates GitHub added in June to block lifecycle scripts, and installation looks clean to static scanners. Once triggered, it fingerprints the host, exfiltrates details over hardcoded Slack and Telegram channels, and polls an Ethereum Sepolia smart contract for encrypted second-stage commands.

Check
Audit dependency trees for indexed-btree and typosquats of sorted-btree, then remove them and rotate any credentials exposed to affected build or runtime hosts.
Affected
Projects that installed indexed-btree run the loader the first time application code calls the tree, giving attackers host fingerprinting and staged command execution.
Fix
Pin dependencies to reviewed versions, scan for runtime-triggered loaders not just install scripts, and block outbound Slack, Telegram, and testnet RPC from build hosts.

Shai-Hulud npm worm now hunts credentials across 469 different locations

Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.

Check
Scan your dependencies and lockfiles for known-compromised packages, rotate any credentials that a developer machine or pipeline can reach, and reduce the number of long-lived secrets stored in reachable configuration files.
Affected
Developers and CI/CD systems that install compromised npm packages; the worm harvests credentials from 469 locations across developer, pipeline, cloud, and AI-tool configurations, then uses them to spread and steal further secrets.
Fix
Pin and vet dependencies, use scoped short-lived tokens instead of long-lived secrets, isolate build environments, monitor for credential access during installs, and keep secrets out of files developer and AI tools read.

Attackers abuse npm and its mirrors to host fake CAPTCHA phishing pages

Researchers at OX Security found a campaign using two dozen npm packages as free phishing infrastructure rather than as malware aimed at developers. Each package is just a single HTML page, harmless to install, but once served through npm content-delivery mirrors like unpkg it becomes a live, fully rendered fake Cloudflare CAPTCHA page hosted on a trusted domain. The page then redirects victims to ClickFix-style phishing infrastructure, and while it currently forwards to a legitimate site, it can be reconfigured to deliver any phishing payload. The trick is not infecting people who install the packages, but abusing the registry and its mirrors as validated, reputable storage for attacker content.

Check
Treat fake CAPTCHA and ClickFix pages as hostile even when served from trusted domains like unpkg, and educate users not to run commands or steps a CAPTCHA prompt tells them to perform.
Affected
Anyone lured to a fake CAPTCHA page hosted on a trusted npm mirror; the pages redirect to ClickFix phishing, exploiting the reputation of legitimate infrastructure to bypass suspicion and some blocking.
Fix
Monitor and filter for HTML content served from package-mirror domains, block known phishing and ClickFix infrastructure, apply reputation-aware web filtering rather than trusting domains outright, and train users on fake CAPTCHA lures.

Fake npm calendar tools drop an AI-assisted Linux backdoor on import

Trend Micro found 14 malicious npm packages that pose as working calendar and streak utilities while secretly installing a Linux backdoor from the commercial RedC2 4.0 toolkit. The packages function as advertised, but on load they locate a bundled binary disguised as a math accelerator, mark it executable, and run it as a detached background process. No install script is needed, so a single import anywhere in the dependency graph, even a transitive one, triggers execution. RedC2 is sold on criminal forums as an evasion-focused command-and-control framework with surveillance, credential theft, tunneling, in-memory payload execution, and AI-assisted command features. It shows how import-time execution keeps making package registries an easy delivery route.

Check
Audit npm dependencies, including transitive ones, for the malicious calendar packages and any bundled binaries, and remove them, since simply importing one runs the backdoor without an install script.
Affected
Developers and systems that installed the trojanized npm calendar packages; importing one anywhere in the dependency tree drops and runs a RedC2 Linux backdoor with surveillance, credential theft, and remote-control capabilities.
Fix
Pin and vet dependencies, watch for packages that bundle binaries or spawn detached processes on import, use lockfiles and isolated builds, and monitor developer and CI hosts for unexpected outbound connections.

Self-spreading npm worm ChainDrop poisons over 1,300 package versions in hours

A self-propagating worm named ChainDrop tore through the npm registry on August 4, poisoning packages that huge parts of the software world depend on. It began by hijacking the GitHub account behind keyv, a caching library pulled in about 150 million times a week, then spread to sibling and downstream packages, reaching over 1,300 poisoned versions with billions of monthly downloads within hours. A preinstall script harvests credentials from developer and continuous integration environments, including AI agent tokens, cloud keys, and self-hosted CI secrets, then uses stolen npm publishing access to poison more packages. A descendant of the earlier Shai-Hulud worm, it even forged valid-looking build provenance.

Check
Compare lockfiles and resolved versions against the published affected-package list, and treat any machine that installed a poisoned version as compromised, but remove the malware's token watcher before rotating anything.
Affected
Developers and CI systems that installed a poisoned version during the attack window; the worm steals repository, registry, cloud, AI agent, and private-key credentials, then self-spreads through npm publishing access.
Fix
Rotate all reachable credentials after removing the token watcher, install with scripts disabled, pin and delay adoption of new versions, and check for injected hooks in developer tooling and continuous integration configuration.

Malicious npm packages split a RAT across files to slip past code review

Researchers at Socket found 18 malicious npm packages that deliver a cross-platform remote access trojan to users of Alibaba developer tools, splitting the attack across many packages so each looks harmless on its own. Ten lure packages with no real function depend on a bridge package, which pulls in loaders that fetch a rule-engine configuration from GitHub and use it to run OS-specific payloads from a server disguised as Alibaba infrastructure. On Windows it even replaces a legitimate Alibaba security app with a trojanized copy. The final trojan can steal data, run commands, and move laterally, and the campaign stayed hidden for about three months.

Check
Analyze dependency trees as a whole rather than one package at a time, since this campaign hid its logic across lure, bridge, and loader packages that each look benign in isolation.
Affected
Developers using Alibaba tooling who installed the malicious packages; the fragmented loader assembles a remote access trojan that steals data, runs commands, and moves laterally, evading per-package review.
Fix
Vet dependencies and their transitive graph, watch for packages that only pull in others or fetch configuration from external repositories, pin trusted versions, and monitor developer machines for unexpected outbound connections.

Amazon ties the chalk and debug npm hijacks to North Korean hackers

Amazon's threat intelligence team linked several major npm supply chain attacks to a North Korean group tracked as Sapphire Sleet, also known as BlueNoroff. The group compromised the small typo-crypto package in March 2025 as a test, then hijacked the hugely popular debug and chalk packages in September 2025, and axios in March 2026. The debug and chalk incident, which pushed a wallet-draining script into packages with billions of weekly downloads, reached roughly one in ten cloud environments within two hours. The attackers gained access by phishing package maintainers through lookalike npm domains, then published malicious versions that auto-installing projects pulled in.

Check
Review whether your projects or CI pulled compromised versions of typo-crypto, debug, chalk, or axios during the affected periods, and check developer and build environments for wallet-draining or credential-stealing behavior.
Affected
Developers and organizations that auto-install npm dependencies; a phished maintainer account can push a malicious version of a hugely popular package that reaches thousands of downstream environments within hours.
Fix
Pin and verify dependencies, add a delay before adopting new versions, watch for maintainer-account phishing, protect publishing accounts with phishing-resistant MFA, and monitor build environments for credential and wallet theft.

Compromised joyfill npm packages run a remote access trojan when imported

Attackers published malicious versions of the @joyfill/components and @joyfill/layouts npm packages that run a remote access trojan as soon as the package is imported, not merely installed. Because the payload executes at import time, defenses that block install scripts, such as installing with scripts disabled, do not stop it. The malicious code sat only in the published tarballs with no matching source change, pointing to a registry or publishing pipeline compromise. Once loaded, it profiles the host, opens a remote-control channel, and can run shell commands, upload files, read the clipboard, and tamper with developer tools, using blockchain networks to resolve its next payload for resilience.

Check
Check whether any project, CI runner, or build imported the malicious @joyfill/components or @joyfill/layouts versions, focusing on import-time execution rather than only install scripts.
Affected
Developers and CI pipelines that imported the compromised joyfill packages; the trojan runs in any process that loads them, giving attackers remote control and access to developer credentials and tools.
Fix
Remove the malicious versions, pin known-good releases, rebuild from clean state, rotate secrets reachable from affected machines, and add runtime and egress monitoring, since install-script controls do not catch import-time payloads.

GitHub delays Dependabot version updates to keep poisoned packages out

GitHub is adding a default three-day cooldown before Dependabot opens pull requests for new package versions, aimed at supply chain attacks where a poisoned release spreads through automated updates before anyone catches it. Security updates that answer a known advisory still ship immediately; only routine version updates wait. GitHub points to the September 2025 compromise of chalk, debug, and other packages, whose crypto-stealing versions were live for roughly two hours, and notes its advisory database logged more than 6,500 npm malware advisories in the year to May 2026, around eighteen a day. Most malicious releases are caught within hours, so a short delay filters out the majority.

Check
If you use Dependabot, confirm the cooldown is enabled and consider tuning the window in dependabot.yml, and apply similar delay logic to any other automated dependency tooling you run.
Affected
Projects with automated dependency updates that pull new releases immediately; a poisoned version of a popular package can reach reviewers and installs during the short window before it is caught and yanked.
Fix
Adopt a cooldown on version updates while keeping security fixes immediate, pin and verify dependencies, review update pull requests rather than auto-merging, and monitor for advisories on packages you rely on.