Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Shadow AI’s Real Threat Is Access Control

June 26, 2026

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026
Facebook X (Twitter) Instagram
Saturday, June 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Malicious npm Code Reached 10% of Cloud Environments
Cyber Security

Malicious npm Code Reached 10% of Cloud Environments

Team-CWDBy Team-CWDSeptember 11, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security experts have warned that a newly discovered supply chain attack targeting npm packages is still active and may already have impacted 10% of cloud environments.

On Monday, a threat actor hijacked the npm account of a well-known developer, “qix,” via social engineering, before publishing trojanized versions of popular packages.

Although these malicious versions, which contained crypto-stealing malware, were removed within just two hours, security vendor Wiz has claimed they managed to reach 1 in 10 cloud environments.

“During the short two-hour timeframe in which the versions were available for download, if they were incorporated into frontend builds and shipped as web assets, any browsers loading the affected website would execute a malicious payload that hooks network and wallet APIs in order to silently rewrite cryptocurrency recipients/approvals before signing, so that transactions would be diverted to attacker-controlled wallets,” the vendor claimed.

“Following the release of the malicious versions, our data shows that the malicious code itself could be found in at least 10% of cloud environments, present in bundles or assets.”

Read more on open source threats: Malicious Open Source Packages Surge 188% Annually

Wiz also cited research from JFrog indicating that the campaign extends beyond qix to other npm accounts.

“After the initial batch of infected packages, we identified a few more compromised accounts, including duckdb, which indicates that the campaign is still active,” the supply chain security vendor wrote.

Malicious packages included @duckdb/node-api@1.3.3, @duckdb/duckdb-wasm@1.29.2, @duckdb/node-bindings@1.3.3, and duckdb@1.3.3. The good news is that these were also removed quickly and received “almost no downloads,” according to JFrog.

No Time to Relax

Users of what is the world’s largest software registry, NPM, were urged to stay vigilant.

“Treat the list as evolving; validate against your registry/mirror and keep blocklists current,” said Wiz.

The cloud security vendor had the following advice for security teams:

  • Blocklist malicious package versions in the private registry/proxy, and pin/override to known-safe versions
  • Rebuild from clean caches (CI + local), clearing all caches on local development machines and CI/CD build servers to prevent any compromised dependencies from being reintroduced from a “poisoned” cache
  • Issue an invalidation command for all affected JavaScript assets on the company Content Delivery Network (CDN), in order to force servers to discard cached malicious files
  • Hotfix the UI by adding client-side checksums/subresource integrity (SRI) where applicable. Temporarily disable tipping/donation modules and force re-auth for wallet flows
  • Hunt for malicious packages by running bundle/asset scans and reviewing signing-flow telemetry for anomalies during 13:16-15:15 UTC on September 8
  • Triage by auto-flagging approvals/transfers to unexpected recipient/spender addresses in that time window and notify impacted users
  • Refresh the npm blocklist daily while the campaign continues, including DuckDB and any newly reported packages



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWhat is it, and how do I get it off my device?
Next Article 61% of US Companies Hit by Insider Data Breaches
Team-CWD
  • Website

Related Posts

Cyber Security

The Security Coverage Gap is a Math Problem

June 26, 2026
Cyber Security

Major Increase in Ransomware Attacks Targeting Europe, Warns Report

June 26, 2026
Cyber Security

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

2025’s most common passwords were as predictable as ever

January 21, 2026

What it is and how to protect yourself

January 8, 2026

Here’s how to avoid a ‘second strike’

April 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.