Account Takeover 2025 Incident #7 CVE-2025-59144

chalk/debug Shai-Hulud phishing

Estimated Financial Impact
$10-50M+
Blast Radius
2B+ combined weekly downloads; CISA alert

What Happened

A sophisticated adversary-in-the-middle phishing attack impersonating npmjs.help captured npm maintainer Josh Junon's credentials and 2FA token. Backdoored versions of 18+ packages including chalk, debug, ansi-styles, and supports-color were published with an obfuscated cryptocurrency wallet hijacker. Combined weekly downloads exceeded 2 billion; malicious versions were downloaded 2.5M+ times in ~2 hours. CISA issued a formal alert.

Sources: JFrog analysis · StepSecurity documentation · CISA alert

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_SINGLE_CONTRIBUTOR pre-existing

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTSSOURCE_SINGLE_CONTRIBUTOR

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_SINGLE_CONTRIBUTOR pre-existing
Sonatype (Nexus) Partial Firewall blocks after signature; not proactive
Socket Caught First to detect Shai-Hulud worm; behavioral analysis
Snyk Missed No malware detection
Black Duck Missed No malware detection
Endor Labs Missed No malware detection
← bootstrap-sass gem @solana/web3.js →