Software Development

The Alarming Rise of Malicious NPM Packages Reveals a New Level of Software Supply Chain Risk

The Alarming Rise of Malicious NPM Packages Reveals a New Level of Software Supply Chain Risk

Attackers used typosquatting—altered names of popular npm packages—to distribute 60 malicious packages targeting developers and CI/CD environments. Malicious post-install scripts quietly exfiltrated developer and network information without executing obvious malware or escalating privileges. Roughly 3,000 downloads exposed sensitive data, highlighting significant supply
26 May 2025