ended5월 19일· 1 sources

Massive npm Supply Chain Attack Compromises 314 Packages Through Account Hijacking

npm 패키지 314개 동시 침해, 22분 만에 악성 버전 631개 배포

Why it matters

A sophisticated attack targeting a single npm package maintainer resulted in the compromise of 314 packages and deployment of 631 malicious versions within 22 minutes, stealing critical credentials including AWS keys, GitHub tokens, and SSH keys. The malware's capability to escape containerized environments when Docker sockets are exposed creates severe risks for enterprise infrastructure. This incident reveals fundamental vulnerabilities in the open-source package ecosystem's security model and underscores the urgent need for stronger maintainer identity verification and supply chain protection mechanisms.

1
Sources
+0
24h
Growth
125d
Active
supply chain attacknpm compromisecredential theftcontainer escapeprivilege escalation

Sources

Related Issues