Close Menu
primehub.blog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Most-Saved Recipes in the Epicurious App This Year (2025)

    December 22, 2025

    What to Wear in Dubai, According to Stylist Oumayma Elboumeshouli

    December 22, 2025

    10 of the Best Interior Design Books I’m Loving Right Now | Wit & Delight

    December 22, 2025
    Facebook X (Twitter) Instagram
    primehub.blog
    Trending
    • The Most-Saved Recipes in the Epicurious App This Year (2025)
    • What to Wear in Dubai, According to Stylist Oumayma Elboumeshouli
    • 10 of the Best Interior Design Books I’m Loving Right Now | Wit & Delight
    • Effective communication with patients managing mental health issues
    • White House Cheers ‘America First’ Jobs Shift As Hiring Slows And Federal Payrolls Shrink
    • 23 Classic and Modern French Recipes You Can Make at Home
    • How To Make Pine-Infused Vinegar For Cleaning
    • Programming the Oxocard Connect with Arduino
    • Home
    • Health
    • Finance
    • Lifestyle
    • Food
    • Travel
    • DIY
    • Eco Living
    • Tech
    primehub.blog
    Home » Software packages with more than 2 billion weekly downloads hit in supply-chain attack
    Tech

    Software packages with more than 2 billion weekly downloads hit in supply-chain attack

    PrimeHubBy PrimeHubSeptember 9, 2025No Comments2 Mins Read0 Views
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email
    Software packages with more than 2 billion weekly downloads hit in supply-chain attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to be the world’s biggest supply-chain attack ever.

    The attack, which compromised nearly two dozen packages hosted on the npm repository, came to public notice on Monday in social media posts. Around the same time, Josh Junon, a maintainer or co-maintainer of the affected packages, said he had been “pwned” after falling for an email that claimed his account on the platform would be closed unless he logged into a site and updated his two-factor authentication credentials.

    Defeating 2FA the easy way

    “Sorry everyone, I should have paid more attention,” Junon, who uses the moniker Qix, wrote. “Not like me; have had a stressful week. Will work to get this cleaned up.”

    The unknown attackers behind the account compromise wasted no time capitalizing on it. Within an hour’s time, dozens of open source packages Junon oversees had received updates that added malicious code for transferring cryptocurrency payments to attacker-controlled wallets. With more than 280 lines of code, the addition worked by monitoring infected systems for cryptocurrency transactions and chaining the addresses of wallets receiving payments to those controlled by the attacker.

    The packages that were compromised, which at last count numbered 20, included some of the most foundational code driving the JavaScript ecosystem. They are used outright and also have thousands of dependents, meaning other npm packages that don’t work unless they are also installed. (npm is the official code repository for JavaScript files.)

    “The overlap with such high-profile projects significantly increases the blast radius of this incident,” researchers from security firm Socket said. “By compromising Qix, the attackers gained the ability to push malicious versions of packages that are indirectly depended on by countless applications, libraries, and frameworks.”

    The researchers added: “Given the scope and the selection of packages impacted, this appears to be a targeted attack designed to maximize reach across the ecosystem.”

    The email message Junon fell for came from an email address at support.npmjs.help, a domain created three days ago to mimic the official npmjs.com used by npm. It said Junon’s account would be closed unless he updated information related to his 2FA—which requires users to present a physical security key or supply a one-time passcode provided by an authenticator app in addition to a password when logging in.

    attack Billion downloads Hit packages software supplychain weekly
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    PrimeHub
    • Website

    Related Posts

    Finance

    Trump Still Plans To Use Tariffs For Dividend Checks And To Eliminate Income Tax; Even As Revenues Hit $215B And The Supreme Court Weighs In

    December 3, 2025
    Finance

    Trump Accounts Just Got A $6.25 Billion Boost And Here’s How Kids Could Become Millionaires

    December 3, 2025
    Finance

    California’s $18 Billion Budget Hole Puts Newsom’s Presidential Ambitions At Risk

    November 23, 2025
    Tech

    33 Best STEM Toys for Kids (2025): Make Learning Fun

    November 18, 2025
    Tech

    Proton VPN two-year plans are up to 75 percent off

    November 15, 2025
    Tech

    Ubisoft continues its partnership with mental health charity Safe In Our World with new Good Game Playbooks to promote positive online play and protect from disruptive behaviour

    November 12, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Editor's Picks

    The Most-Saved Recipes in the Epicurious App This Year (2025)

    December 22, 2025

    What to Wear in Dubai, According to Stylist Oumayma Elboumeshouli

    December 22, 2025

    10 of the Best Interior Design Books I’m Loving Right Now | Wit & Delight

    December 22, 2025

    Effective communication with patients managing mental health issues

    December 22, 2025
    Latest Posts

    20 Best Hotels in Tulum, From Luxury Resorts to Beach Bungalows

    August 24, 2025

    Things I Love at the Library

    August 24, 2025

    How to Test for Mold (Even If You Can’t See It)

    August 24, 2025
    Facebook Pinterest WhatsApp Instagram

    News

    • DIY
    • Eco Living
    • Finance
    • Food
    • Health

    catrgories

    • Lifestyle
    • Tech
    • Travel
    • DIY
    • Eco Living

    useful link

    • About Us
    • Contact us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 primehub.blog. Designed by Pro.
    • About Us
    • Contact us
    • Disclaimer
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.