Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins Without a Single Phishing Email

    July 30, 2026

    New York vs Florida: Which State Is Better to Move To?

    July 30, 2026

    What State Is Best to Invest in Real Estate in 2026?

    July 30, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»Software packages with more than 2 billion weekly downloads hit in supply-chain attack
    Tech News

    Software packages with more than 2 billion weekly downloads hit in supply-chain attack

    Michael ComaousBy Michael ComaousSeptember 9, 20252 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Software packages with more than 2 billion weekly downloads hit in supply-chain attack
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to be the world’s biggest supply-chain attack ever.

    The attack, which compromised nearly two dozen packages hosted on the npm repository, came to public notice on Monday in social media posts. Around the same time, Josh Junon, a maintainer or co-maintainer of the affected packages, said he had been “pwned” after falling for an email that claimed his account on the platform would be closed unless he logged into a site and updated his two-factor authentication credentials.

    Defeating 2FA the easy way

    “Sorry everyone, I should have paid more attention,” Junon, who uses the moniker Qix, wrote. “Not like me; have had a stressful week. Will work to get this cleaned up.”

    The unknown attackers behind the account compromise wasted no time capitalizing on it. Within an hour’s time, dozens of open source packages Junon oversees had received updates that added malicious code for transferring cryptocurrency payments to attacker-controlled wallets. With more than 280 lines of code, the addition worked by monitoring infected systems for cryptocurrency transactions and chaining the addresses of wallets receiving payments to those controlled by the attacker.

    The packages that were compromised, which at last count numbered 20, included some of the most foundational code driving the JavaScript ecosystem. They are used outright and also have thousands of dependents, meaning other npm packages that don’t work unless they are also installed. (npm is the official code repository for JavaScript files.)

    “The overlap with such high-profile projects significantly increases the blast radius of this incident,” researchers from security firm Socket said. “By compromising Qix, the attackers gained the ability to push malicious versions of packages that are indirectly depended on by countless applications, libraries, and frameworks.”

    The researchers added: “Given the scope and the selection of packages impacted, this appears to be a targeted attack designed to maximize reach across the ecosystem.”

    The email message Junon fell for came from an email address at support.npmjs.help, a domain created three days ago to mimic the official npmjs.com used by npm. It said Junon’s account would be closed unless he updated information related to his 2FA—which requires users to present a physical security key or supply a one-time passcode provided by an authenticator app in addition to a password when logging in.

    Recommended for you:

    Ted Cruz Wants to Help AI Companies Duck Regulations
    Tech News·Sep 10, 2025

    Ted Cruz Wants to Help AI Companies Duck Regulations

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleBluesky finally has a private bookmarking feature
    Next Article Massive Leak Shows How a Chinese Company Is Exporting the Great Firewall to the World
    Michael Comaous
    • Website

    Michael Comaous is a dedicated professional with a passion for technology, innovation, and creative problem-solving. Over the years, he has built experience across multiple industries, combining strategic thinking with hands-on expertise to deliver meaningful results. Michael is known for his curiosity, attention to detail, and ability to explain complex topics in a clear and approachable way. Whether he’s working on new projects, writing, or collaborating with others, he brings energy and a forward-thinking mindset to everything he does.

    Related Posts

    7 Mins Read

    Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins Without a Single Phishing Email

    5 Mins Read

    Microsoft’s Biggest Patch Tuesday Ever Just Showed Us Where Cybersecurity Is Heading

    6 Mins Read

    DeepMind’s Demis Hassabis Wants a Wall Street-Style Watchdog for AI

    3 Mins Read

    Eye Drops That Dissolve Cataracts Without Surgery? The Australian Breakthrough That Isn’t

    7 Mins Read

    Crashing the Boys’ Club: Why Cybersecurity Is Finally Opening Its Doors to Career Changers

    6 Mins Read

    Telecom Giants Form C2 ISAC to Fight the Next Salt Typhoon

    Top Posts

    Japan Skips Exams Until Age 10 and Teaches Character Instead. The Results Are Complicated.

    July 29, 20268 Views

    Husbands Cause More Stress Than Kids? Science Says Many Moms Feel Exactly That

    July 28, 20268 Views

    Best Stores for Buying MP3 and Digital Music You Can Keep Forever (2026)

    August 2, 20258 Views
    Stay In Touch
    • Facebook

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Stores for Buying MP3 and Digital Music You Can Keep Forever (2026)

    August 2, 2025905 Views

    Discord will require a face scan or ID for full access next month

    February 9, 2026770 Views

    Trade in your old phone and get up to $1,100 off a new iPhone 17 at AT&T – here’s how

    September 10, 2025382 Views
    Our Picks

    Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins Without a Single Phishing Email

    July 30, 2026

    New York vs Florida: Which State Is Better to Move To?

    July 30, 2026

    What State Is Best to Invest in Real Estate in 2026?

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 GeekBlog

    Type above and press Enter to search. Press Esc to cancel.