ADVERTISEMENT

Massive supply chain attack hits NPM as hackers target 18 packages downloaded 2B times weekly

What has been dubbed the largest supply chain attack in history has hit NPM, one of the most prolific JavaScript package managers.

Phishing attack, hackers

Image by Cybernews

Niamh Ancell
Niamh Ancell Journalist
September 9, 2025 Updated: September 9, 2025 4 min read

Yep, I've been pwned. 2FA reset email, looked very legitimate. Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.

[image or embed]

undefined Josh Junon (@bad-at-computer.bsky.social) September 8, 2025 at 6:15 PM
Niamh Ancell vilius Ernestas Naprys Paulina Okunyte
Don't miss our latest stories on Google News
Add us as your Preferred Source on Google.

Which packages did the NPM supply chain attack affect?

  • backslash
  • chalk-template
  • supports-hyperlinks
  • has-ansi
  • simple-swizzle
  • color-string
  • error-ex
  • color-name
  • is-arrayish
  • slice-ansi
  • color-convert
  • wrap-ansi
  • ansi-regex
  • supports-color
  • strip-ansi
  • chalk
  • debug
  • ansi-styles

What actually happened during the NPM supply chain attack?

ADVERTISEMENT

Bitcoin and crypto users affected by NPM supply chain attack

ADVERTISEMENT