ADVERTISEMENT

Supply chain hit once again: single NPM account pushes 600+ compromised packages, used by millions

Another massive supply chain attack is spreading. Hundreds of compromised NPM packages are being detected, with hackers using stolen secrets to create over 2,200 public GitHub repositories, all because TeamPCP hijacked a single maintainer’s account.

NPM supply chain attack

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
May 19, 2026 Updated: May 19, 2026 4 min read
  • jest-canvas-mock (2.4 million weekly downloads) is used by developers to test graphics code without a browser
  • jest-date-mock (381,400 weekly downloads) is a tool for simulating date and time in automated tests
  • echarts-for-react (890,000 weekly downloads) is a package that helps embed interactive charts into web applications
  • size-sensor (970,000 weekly downloads) is a utility that resizes charts and other elements

A single maintainer got compromised

Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

Hackers are after crypto wallets and secrets

  • Cloud credentials for AWS, Google Cloud Platform, Azure, and Terraform
  • SSH keys (private keys and host authentication files)
  • Developer tokens for NPM, PYPI, NET, Git credentials, and Docker configs
  • Kubernetes configs, credentials, service account tokens, and secrets across all namespaces
  • Crypto wallets
  • Chat messaging configuration files and tokens, including Slack, Telegram, and Discord
  • AI tool configurations for Claude, etc
ADVERTISEMENT

NPM supply chain attacks becoming a running joke


ADVERTISEMENT