ReversingLabs detailed a malicious npm package, tw-pkgprobe-7731, that masquerades as an authorized Twilio bug-bounty research probe while harvesting developer data. Uploaded in mid-August by an account that no longer exists, it shipped eleven versions within about 45 minutes. Comments inside describe it as an authorized HackerOne probe that runs only inside Twilio's serverless sandbox and takes no destructive action. On execution it first checks for a Twilio developer environment and exits otherwise, then collects environment variables plus system details like mounts and temporary folders and exfiltrates them through a webhook. Later versions specifically target developers using Twilio APIs by searching for folders tied to particular Twilio account identifiers, sharpening the credential theft.
Checkmarx found an ongoing npm campaign built around indexed-btree, a package impersonating the popular sorted-btree library that has amassed two million weekly downloads. Instead of using preinstall or postinstall scripts, the malware hides its loader inside the BTree.prototype.set method that applications call constantly, so it executes at runtime rather than install time. This sidesteps the npm approval gates GitHub added in June to block lifecycle scripts, and installation looks clean to static scanners. Once triggered, it fingerprints the host, exfiltrates details over hardcoded Slack and Telegram channels, and polls an Ethereum Sepolia smart contract for encrypted second-stage commands.
Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.
Researchers at OX Security found a campaign using two dozen npm packages as free phishing infrastructure rather than as malware aimed at developers. Each package is just a single HTML page, harmless to install, but once served through npm content-delivery mirrors like unpkg it becomes a live, fully rendered fake Cloudflare CAPTCHA page hosted on a trusted domain. The page then redirects victims to ClickFix-style phishing infrastructure, and while it currently forwards to a legitimate site, it can be reconfigured to deliver any phishing payload. The trick is not infecting people who install the packages, but abusing the registry and its mirrors as validated, reputable storage for attacker content.
Trend Micro found 14 malicious npm packages that pose as working calendar and streak utilities while secretly installing a Linux backdoor from the commercial RedC2 4.0 toolkit. The packages function as advertised, but on load they locate a bundled binary disguised as a math accelerator, mark it executable, and run it as a detached background process. No install script is needed, so a single import anywhere in the dependency graph, even a transitive one, triggers execution. RedC2 is sold on criminal forums as an evasion-focused command-and-control framework with surveillance, credential theft, tunneling, in-memory payload execution, and AI-assisted command features. It shows how import-time execution keeps making package registries an easy delivery route.
A self-propagating worm named ChainDrop tore through the npm registry on August 4, poisoning packages that huge parts of the software world depend on. It began by hijacking the GitHub account behind keyv, a caching library pulled in about 150 million times a week, then spread to sibling and downstream packages, reaching over 1,300 poisoned versions with billions of monthly downloads within hours. A preinstall script harvests credentials from developer and continuous integration environments, including AI agent tokens, cloud keys, and self-hosted CI secrets, then uses stolen npm publishing access to poison more packages. A descendant of the earlier Shai-Hulud worm, it even forged valid-looking build provenance.
Researchers at Socket found 18 malicious npm packages that deliver a cross-platform remote access trojan to users of Alibaba developer tools, splitting the attack across many packages so each looks harmless on its own. Ten lure packages with no real function depend on a bridge package, which pulls in loaders that fetch a rule-engine configuration from GitHub and use it to run OS-specific payloads from a server disguised as Alibaba infrastructure. On Windows it even replaces a legitimate Alibaba security app with a trojanized copy. The final trojan can steal data, run commands, and move laterally, and the campaign stayed hidden for about three months.
Amazon's threat intelligence team linked several major npm supply chain attacks to a North Korean group tracked as Sapphire Sleet, also known as BlueNoroff. The group compromised the small typo-crypto package in March 2025 as a test, then hijacked the hugely popular debug and chalk packages in September 2025, and axios in March 2026. The debug and chalk incident, which pushed a wallet-draining script into packages with billions of weekly downloads, reached roughly one in ten cloud environments within two hours. The attackers gained access by phishing package maintainers through lookalike npm domains, then published malicious versions that auto-installing projects pulled in.
Attackers published malicious versions of the @joyfill/components and @joyfill/layouts npm packages that run a remote access trojan as soon as the package is imported, not merely installed. Because the payload executes at import time, defenses that block install scripts, such as installing with scripts disabled, do not stop it. The malicious code sat only in the published tarballs with no matching source change, pointing to a registry or publishing pipeline compromise. Once loaded, it profiles the host, opens a remote-control channel, and can run shell commands, upload files, read the clipboard, and tamper with developer tools, using blockchain networks to resolve its next payload for resilience.
GitHub is adding a default three-day cooldown before Dependabot opens pull requests for new package versions, aimed at supply chain attacks where a poisoned release spreads through automated updates before anyone catches it. Security updates that answer a known advisory still ship immediately; only routine version updates wait. GitHub points to the September 2025 compromise of chalk, debug, and other packages, whose crypto-stealing versions were live for roughly two hours, and notes its advisory database logged more than 6,500 npm malware advisories in the year to May 2026, around eighteen a day. Most malicious releases are caught within hours, so a short delay filters out the majority.