Committed files replace NPM packages with a combined 2 billion weekly discharges




  • More than a dozen NPM popular packages were committed to a phishing -based supply chain attack
  • Cryptographic users led by malware kidnapping wallet addresses during transactions
  • Some called him the most widespread NPM commitment to date, affecting 2 billion weekly discharges

More than a dozen NPM packages with two billion downloads per week were committed to a supply chain attack that went to cryptocurrency users.

Aikido Security researchers saw a QIX maintainer account (real name Josh Junon) publishing malicious updates. In less than an hour, multiple versions were loaded, and shortly after Junon himself confirmed the attack and apologized for the disaster,

Leave a Comment

Your email address will not be published. Required fields are marked *