Skip to content
Tech News
← Back to articles

New npm supply-chain attack self-spreads to steal auth tokens

read original get npm Security Audit Tool → more articles
Why This Matters

This new npm supply-chain attack highlights the growing sophistication of cyber threats targeting open-source ecosystems, emphasizing the need for developers and organizations to enhance security measures. The attack's ability to self-spread and steal sensitive developer credentials poses significant risks to software integrity and data security across the tech industry and consumer applications.

Key Takeaways

A new supply chain attack targeting the Node Package Manager (npm) ecosystem is stealing developer credentials and attempting to spread through packages published from compromised accounts.

The threat was spotted by researchers at application security companies Socket and StepSecurity in multiple packages from Namastex Labs, a company that provides AI-based agentic solutions designed to improve profitability.

Socket noted that the techniques used for credential theft, data exfiltration, and self-propagation were similar with TeamPCP’s CanisterWorm attacks, but available evidence could not lead to confident attribution.

At publishing time, Socket lists a set of 16 Namastex packages already compromised in the new supply-chain attack:

@automagik/genie (4.260421.33-4.260421.39)

pgserve (1.1.11–1.1.13)

@fairwords/websocket (1.0.38-1.0.39)

@fairwords/loopback-connector-es (1.4.3-1.4.4)

@openwebconcept/[email protected]

@openwebconcept/[email protected]

... continue reading