New York

October 15–17, 2025

Berlin

November 3–4, 2025

London

June 2–3, 2026

Another npm attack highlights the need for supply-chain security

Time to rotate those credentials.
September 18, 2025

Estimated reading time: 3 minutes

A fast-moving worm has compromised more than 180 npm packages – and may mark a turning point for software supply chain security

After years of high-profile package compromises – from event-stream to the recent Nx breach – npm is once again in the spotlight. Over the past week, a self-replicating worm has made its way through the world’s largest JavaScript package repository, compromising at least 180 packages and exposing credentials from maintainers and developers along the way. 

Because many of the affected packages sit deep in dependency chains, the attack is likely to have touched thousands of downstream applications and developers – far more than the raw number of packages suggests.

Join LeadDev.com for free to access this content

Create an account to access our free engineering leadership content, free online events and to receive our weekly email newsletter. We will also keep you up to date with LeadDev events.

Register with google

We have linked your account and just need a few more details to complete your registration:

Terms and conditions

 

 

Enter your email address to reset your password.

 

A link has been emailed to you - check your inbox.



Don't have an account? Click here to register