DuckDB npm Account Breached in Ongoing Supply Chain Attack with Wallet-Drainer Malware
By
feross
Pulled from the oven just right. Trustworthy, fact-dense, deeply satisfying.
Summary
The ongoing npm supply chain attack that previously compromised prolific author Qix has now spread to the DuckDB npm account (duckdb_admin). Multiple malicious versions of DuckDB-related packages were published on September 9, 2025, containing the same wallet-drainer malware used in the Qix compromise, indicating a coordinated campaign. Several packages were affected, with some having negligible downloads while others potentially impacted more users.
Key quotes
· 3 pulledThe ongoing npm supply chain attack that compromised prolific author Qix has now spread to another high-profile maintainer.
The injected code is the same wallet-drainer malware used in the Qix compromise, strongly indicating this is part of the same campaign.
The npm account duckdb_admin, responsible for DuckDB-related packages, was breached and multiple malicious versions were published.
You might also wanna read

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
Attacker publishes 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries
A single npm user published 14 malicious packages over four hours, impersonating popular OpenSearch, Elasticsearch, DevOps, and environment-
176 malicious npm packages used dependency confusion to target internal dependencies and steal credentials
Sonatype researchers uncovered a campaign involving 176 malicious npm packages using a dependency confusion attack strategy. Attackers publi
Microsoft detects 14 malicious npm packages impersonating OpenSearch and Elasticsearch libraries
A threat actor using the alias vpmdhaj published 14 malicious npm packages within four hours, impersonating legitimate OpenSearch, Elasticse
