A sophisticated adversary-in-the-middle phishing attack impersonating npmjs.help captured npm maintainer Josh Junon's credentials and 2FA token. Backdoored versions of 18+ packages including chalk, debug, ansi-styles, and supports-color were published with an obfuscated cryptocurrency wallet hijacker. Combined weekly downloads exceeded 2 billion; malicious versions were downloaded 2.5M+ times in ~2 hours. CISA issued a formal alert.
Sources: JFrog analysis · StepSecurity documentation · CISA alert
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_SINGLE_CONTRIBUTOR pre-existing
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_SINGLE_CONTRIBUTOR pre-existing |
| Sonatype (Nexus) | Partial | Firewall blocks after signature; not proactive |
| Socket | Caught | First to detect Shai-Hulud worm; behavioral analysis |
| Snyk | Missed | No malware detection |
| Black Duck | Missed | No malware detection |
| Endor Labs | Missed | No malware detection |