Compromised JavaScript Package Caught Stealing npm Credentials

Found on Bleeping Computer on Friday, 13 July 2018
Browse Software

A hacker has gained access to a developer's npm account and injected malicious code into a popular JavaScript library, code that was designed to steal the npm credentials of users who utilize the poisoned package inside their projects.

"We determined that access tokens for approximately 4,500 accounts could have been obtained before we acted to close this vulnerability. However, we have not found evidence that any tokens were actually obtained or used to access any npmjs.com account during this window," Silverio said.

This is the third incident in the past year when a hacker has inserted malicious code in an npm package.

The sooner NPM vanishes, the better.