Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. In a report published May 5, 2021, Snyk described a research activity that found eight npm packages whose installation scripts could run arbitrary commands. Snyk said it reported them to npm for flagging and removal. The finding is historical: it does not establish the current registry status or safety of any package or version.

What Snyk reported

Snyk’s analysis identified eight packages using preinstall or postinstall scripts to run commands during installation:

  • radar-cms
  • rcenodejs
  • paychex-framework-forms
  • paychex-framework-core-ui
  • paychex-framework-approvals
  • paychex-framework
  • paychex-common-npm
  • paychex-app-common-html

Eight is the count in this specific May 2021 report, not an estimate of how common malicious packages are across npm. Snyk described three reported behaviors:

  • radar-cms had a postinstall command that attempted to send files such as ~/.kube/config, package.json, /etc/passwd, /tmp/krb5cc_0 and /etc/hosts to a remote endpoint.
  • The listed paychex-* packages reportedly used a preinstall hook to send environment variables to a remote server.
  • rcenodejs reportedly used a preinstall script to create a reverse shell.

These are findings attributed to Snyk’s analysis of the packages, not a current assessment of their registry listings. Snyk’s May 5, 2021 report contains the original account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why installation scripts matter

Package lifecycle scripts can run commands at installation time. That means a package can attempt an action as soon as a developer or automated build installs it; the reported behavior does not necessarily require someone to open a file or click a link. The impact depends on the command and the environment in which installation runs. The examples Snyk described included attempts to transmit local files or environment variables, and a reverse shell.

Not every malicious package works this way. Snyk’s later overview distinguishes install-hook cases from some phishing packages that require a person to follow a link. To assess a report, look at what triggers the behavior, whether additional user action is required, and what data or access is targeted. Snyk’s later overview discusses those broader patterns.

How to reduce exposure to install-hook attacks

Disable lifecycle scripts when appropriate

For the specific install-script vector in its 2021 report, Snyk recommended:

  • npm install --ignore-scripts
  • yarn install --ignore-scripts

These options are a mitigation for ordinary package lifecycle scripts, not a guarantee against every installation, build, or runtime attack. Disabling scripts can also prevent legitimate packages from completing setup, so use it where it fits your workflow and investigate any resulting installation failures.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check packages before adding them

  • Verify the exact package name before installing; watch for typosquatting and unusually high version numbers.
  • Inspect package source and review what lifecycle scripts do.
  • Scan projects regularly and look up package warnings. Snyk’s 2021 article pointed readers to Snyk Advisor as a way to check whether a package has been flagged malicious. Treat a lookup as one signal, not proof that a package is safe; the cited sources do not establish that any scanner detects every malicious package.

What Snyk’s later figures do—and do not—show

Snyk’s later publications give context for its ongoing package-malware reporting, but their totals should not be conflated with the eight-package 2021 report or treated as a standardized measure of user harm.

  • In a March 23, 2023 article, Snyk reported more than 9,900 impactful malicious packages added in 2022 and 2023, compared with 82 in 2021, and described an 11,973% increase. The article said greater investment in identifying packages contributed to the rise, so the change is not a clean measure of attacker activity alone.
  • An editor’s note dated March 5, 2025, said Snyk identified over 3,600 malicious packages in 2024, primarily targeting npm (3,000+) and PyPI (600+).
  • The same note said more than 1,000 new cases had been flagged so far in 2025, with JavaScript still the most affected ecosystem.
  • It also said around 6,800 malicious packages had been documented across PyPI and npm since the beginning of 2023, almost 860 of them discovered by Snyk.

These are figures Snyk published about its own database and research. The cited sources do not provide an independent, standardized estimate of how many packages affected users. Snyk’s 2023 article and 2025 editor’s note give the dates and qualifications for these totals.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How npm handles malware reports

Snyk said it reported the eight packages to npm’s security team to be flagged and removed. npm’s current documentation describes a process that includes confirming a report, removing the package, publishing a security placeholder and publishing an advisory; npm may also decide whether to ban the uploader’s account. That description is npm’s current process, not confirmation of the final disposition of each package from 2021.

For a new report, npm asks reporters to provide the package name, every affected version, a concise description of the effects, and references, commits or code examples that help confirm the report. See npm’s malware-reporting guidance, whose page says it was last edited June 9, 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.