NPM Package Author "qix" Compromised in Ongoing Supply Chain Phishing Attack
By
naugtur
Pulled from the oven just right. Trustworthy, fact-dense, deeply satisfying.
Summary
This article discusses the ongoing issue of phishing attacks targeting NPM package authors, specifically focusing on a compromised author named "qix." The author notes that while these attacks are currently limited to phishing (not more sophisticated exploits), the high download volumes of NPM packages (2-3 billion per week) should raise awareness about supply chain security risks. The article directs readers to a more detailed analysis on Socket.dev rather than providing its own deep technical breakdown.
Key quotes
· 5 pulledYou too can run malware from NPM (I mean without consequences)
Phishing NPM package authors continues, unsurprisingly.
The stakes are not high enough to switch from phishing to anything more advanced
seeing article blurbs say 'Supply chain Attack' next to 'These packages generally receive 2-3 billion downloads per week.' might finally be enough to make an impression, one hopes.
This is not a detailed analysis of the attack, there's plenty of that already.
You might also wanna read
How a botnet abused my open source project's cloud version to phish 14,000 people
The author, who runs an open source project management tool called Kaneo, discovered that a botnet had abused the hosted cloud version of th
AI security audit of FreeBSD kernel reveals 15 bugs including RCEs and a hypervisor escape
An AI audit of FreeBSD uncovered 15 kernel bugs, including 3 remote code execution vulnerabilities, 5 local privilege escalation flaws, and

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Composer and Packagist Introduce New Supply Chain Security Measures After PHP Ecosystem Attacks
Composer and Packagist.org are implementing new security measures to combat rising software supply chain attacks targeting the PHP open-sour
blog.packagist.com·4d agoComposer and Packagist Introduce New Supply Chain Security Measures After PHP Ecosystem Attacks
Composer and Packagist.org are implementing new security measures to combat rising software supply chain attacks targeting the PHP open-sour
blog.packagist.com·4d agoCritical "BadHost" vulnerability in Starlette framework puts millions of AI agents at risk
A critical vulnerability called "BadHost" has been discovered in Starlette, an open source ASGI framework with 325 million weekly downloads.
arstechnica.com·4d ago