Maintainer Faisal Salman's npm account was hijacked (offered for $20K on a Russian forum two weeks prior). Malicious versions installed an XMRig cryptominer and DanaBot credential-stealing trojan. The package had ~8M weekly downloads and ~1B lifetime downloads; companies affected included Facebook, Amazon, Microsoft, and Google. CISA issued an advisory.
Sources: Faisal Salman GitHub issue · Truesec incident response
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Sonatype (Nexus) | Caught | Nexus Firewall blocks known-malicious packages at ingestion |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |