NPM supply chain attack: Compromised packages with billions of weekly downloads

ISGroup Cybersecurity

On September 8, 2025, several highly popular npm packages — including chalk, debug, ansi-styles, color-convert, strip-ansi, and supports-color — were compromised and republished with malicious code. These packages represent fundamental dependencies in the JavaScript ecosystem and, combined, account for billions of weekly downloads. The malicious versions remained online on the npm registry for approximately 2.5 hours before being removed. Due to the popularity of these packages and their use as transitive dependencies, the potential exposure is extremely broad, affecting both application developers and downstream consumers.

Date2025-09-09 13:17:45

Technical Summary

The compromise originated from a targeted phishing campaign against the package maintainer. The attackers sent emails that mimicked npm support, using a fake domain (npmjs.help) to deceive the maintainer and obtain their credentials. Once access to the account was compromised, the attackers were able to publish malicious versions of the affected packages directly to the npm registry.

The compromised packages contained obfuscated malicious code that intercepted both network traffic and application APIs, primarily targeting operations related to cryptocurrencies, through:

  • Hooking cryptocurrency-related APIs;
  • Detecting wallet addresses and transaction details;
  • Replacing legitimate wallet destinations with addresses controlled by the attackers;

Compromised packages and their respective versions:

Name Version
ansi-regex6.2.1
ansi-styles6.2.2
backslash0.2.1
chalk5.6.1
chalk-template1.1.1
color-convert3.1.1
color-name2.0.1
color-string2.1.1
debug4.4.2
error-ex1.3.3
has-ansi6.0.1
is-arrayish0.3.3
simple-swizzle0.2.3
slice-ansi7.1.1
strip-ansi7.1.1
supports-color10.2.1
supports-hyperlinks4.1.1
wrap-ansi9.0.1

Recommendations

  1. Identify and remove compromised versions: Scan for the presence of the packages and versions listed above and clear npm/yarn/pnpm caches.
  2. Enforce the use of lock files: Lock versions (package-lock.json, yarn.lock, pnpm-lock.yaml) to ensure consistent and verified dependency versions across environments and prevent accidental installation of malicious updates.
  3. Strengthen supply chain security: Implement rigorous dependency monitoring, use SBOMs to track any exposures, and implement two-factor authentication (2FA) with hardware keys for maintainer accounts.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert