npm supply chain attacks can start with a package name that looks almost right, but the more consequential route is often through trusted infrastructure: an established maintainer account, a publishing credential, or a build workflow. Once an attacker can publish under a legitimate package’s name—or use stolen developer access to publish more packages—automated installs and downstream dependencies can help spread malicious code. The incidents differ in technique and impact; “industrialized” describes documented automation and repeated propagation, not one universal attack or actor.
How do npm supply chain attacks work?
An npm package can enter a project through several distinct paths. npm’s threat guidance distinguishes malicious lookalike names, public packages that collide with private package names, and malicious changes to established packages. These are not interchangeable risks: each depends on a different mistake or compromise, so no single safeguard covers them all.
- Typosquatting: An attacker publishes a name resembling a popular package and hopes a developer or configuration typo leads to its installation.
- Dependency confusion: A public package is registered with the name of an organization’s private package. Depending on package-manager configuration, the public package may be selected instead of the intended internal one.
- Compromised legitimate package: An attacker gains the ability to publish a release of a real package and adds malicious behavior. Existing reputation and downstream dependencies can make that release more likely to be installed.
- Compromised build workflow: An attacker targets CI automation, including workflows that process untrusted contributions in a context with access to secrets, tokens, or write permissions.
These routes can connect. A malicious install may expose credentials; stolen credentials may then be used to publish further affected versions. In that pattern, the package is not just the payload—it can also be a route into developer and cloud environments.
What makes the threat industrialized?
The term is most useful when tied to observable mechanics: automation, propagation, scale, and repeated ways of compromising trust. It does not mean that every malicious package is part of a coordinated campaign, or that every incident uses the same payload.
#1 Best Overall
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
In September 2025, GitHub described Shai-Hulud as a self-replicating worm that entered npm through compromised maintainer accounts and malicious post-install scripts. CISA’s September 23, 2025 alert said the campaign scanned for credentials, stole GitHub personal access tokens and cloud service API keys, exfiltrated credentials, and used compromised developer access to infect and publish further packages. CISA summarized the scale this way: “A self-replicating worm—publicly known as ‘Shai-Hulud’—has compromised over 500 packages.”
Scale figures need careful interpretation. CISA reported over 500 compromised packages in that campaign. OpenSSF, as reported by Google Cloud, found a 1,444% increase from 2024 to 2025 in identified malicious open-source packages broadly; that statistic is not limited to npm. Neither figure is a count of confirmed infected developer machines.
What do major npm incidents show?
Different incidents illustrate different ways trust can be abused. A package’s download count indicates potential reach, not how many installations were compromised; the outcome also depends on which version was installed and what the payload could do in that environment.
Rank #2
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
| Incident | Entry and behavior | What the reported scale means |
|---|---|---|
| Shai-Hulud, September 2025 | GitHub described compromised maintainer accounts and malicious post-install scripts. CISA reported credential harvesting and automated use of compromised access to publish further affected packages. | CISA reported over 500 compromised packages; this is a package count, not a confirmed victim count. |
color@5.0.1, September 2025 |
A GitHub-reviewed advisory says the color publishing account was taken over after phishing on September 8, 2025. Version 5.0.1 attempted to redirect cryptocurrency transactions in browser environments. |
The advisory says local, server, and command-line environments were not affected by this specific payload. It lists 5.0.2 as patched. |
| Axios, March 2026 | Google Threat Intelligence Group (GTIG) reported that social engineering compromised a maintainer account used to publish malicious Axios versions. | GTIG said the releases were removed within three hours and Axios had more than 100 million weekly downloads. Those downloads indicate potential reach, not confirmed compromised installations. GTIG also reported supporting affected customers in at least 15 industry verticals and 13 countries; those response figures are not an infection count. |
Why the payload matters
The color@5.0.1 advisory describes a browser-focused cryptocurrency-redirection payload. That is materially different from Shai-Hulud’s credential-stealing and self-replication behavior. A package compromise does not, by itself, establish what systems were affected: the version, execution context, and payload determine the exposure.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Why a short exposure window is not the whole story
GTIG reported that the malicious Axios versions were removed within three hours, but removal does not establish that every downstream copy, private mirror, lockfile, or build cache was clean. Nor does the reported weekly download volume show how many users installed the affected versions. These measures describe different things: time before removal, potential popularity, and confirmed impact.
How do attackers get access to trusted packages and workflows?
Maintainer account takeover
npm identifies phishing and expired email domains as relevant account-takeover routes. Public package metadata may retain an old email address after a maintainer changes it, so an email address visible in package metadata is not conclusive proof of the current account owner. npm says it checks for expired domains or invalid MX records and restricts password resets in those cases.
Rank #3
- 【Flexible Port Configuration】1 Gigabit SFP WAN Port + 1 Gigabit WAN Port + 2 Gigabit WAN/LAN Ports plus1 Gigabit LAN Port. Up to four WAN ports optimize bandwidth usage through one device.
- 【Increased Network Capacity】Maximum number of associated client devices – 150,000. Maximum number of clients – Up to 700.
- 【Integrated into Omada SDN】Omada’s Software Defined Networking (SDN) platform integrates network devices including gateways, access points & switches with multiple control options offered – Omada Hardware controller, Omada Software Controller or Omada cloud-based controller(Contact TP-Link for Cloud-Based Controller Plan Details). Standalone mode also applies.
- 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
- 【SDN Compatibility】For SDN usage, make sure your devices/controllers are either equipped with or can be upgraded to SDN version. SDN controllers work only with SDN Gateways, Access Points & Switches. Non-SDN controllers work only with non-SDN APs. For devices that are compatible with SDN firmware, please visit TP-Link website.
Once a publishing account is taken over, the attacker may be able to make a malicious release that appears to come from the package’s normal publisher. Shai-Hulud and the Axios incident demonstrate how compromised maintainer access can be used to publish; they should not be taken as evidence that every package compromise follows the same path.
Publishing credentials
Long-lived or broadly scoped credentials can turn a leak into publishing access. In its 2025 plan for npm security, GitHub described required two-factor authentication for local publishing, seven-day granular tokens, trusted publishing, and deprecation of classic tokens and TOTP-based 2FA as planned hardening. GitHub’s later July 2026 update describes security changes it says it shipped, including safer workflow defaults and added controls. Treat roadmap items and later rollout statements as time-specific: check the current npm and GitHub documentation before relying on a particular authentication requirement or token policy.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →CI workflow compromise
A project’s automation can be an attack route even when its package account is secure. GitHub’s July 28, 2026 article describes “pwn request” patterns in which workflows handle untrusted fork code, and outlines safer checkout defaults and controls over who can trigger workflows. The practical risk is greatest when a workflow processes untrusted input while holding secrets, write access, or cache permissions that an attacker could abuse.
Rank #4
- New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
- Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
- Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
- 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
- Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
How can you protect an npm project at each stage?
Build defenses around the route an attacker would need to use. Account controls reduce takeover risk; publishing controls constrain what stolen access can do; dependency and workflow controls limit exposure; monitoring and response help contain an incident that gets through.
1. Protect maintainer accounts and recovery
- Use strong multifactor authentication and protect the email account and recovery methods tied to npm publishing.
- Treat unexpected support messages, password-reset prompts, and requests to approve a login as suspicious; use the service’s normal sign-in route rather than links in an unsolicited message.
- Review who has publishing access and remove accounts that no longer need it.
- Check npm’s current authentication guidance. npm has described phased mandatory 2FA and enhanced login verification; GitHub’s July 2026 update says high-impact npm accounts enter a 72-hour read-only mode after an email change or use of a 2FA recovery code. These are service policies and rollout claims, not a substitute for checking the current state of a particular account.
2. Constrain publishing credentials
- Prefer short-lived, narrowly scoped credentials over long-lived credentials with broad permissions where the platform supports them.
- Use trusted publishing where supported and appropriate, so publishing can be tied to a configured identity and workflow rather than a reusable secret.
- Keep publishing credentials out of untrusted pull-request workflows and avoid exposing them to jobs that do not need to publish.
- Review the current npm and GitHub rules for local publishing, tokens, and 2FA instead of assuming a 2025 roadmap item remains only planned—or that a later rollout applies identically to every publisher.
3. Reduce dependency-name and version mistakes
- Use npm scopes for private packages. npm recommends scopes to reduce the risk that a public package with the same name will be substituted for an internal dependency.
- Review package names, maintainers, versions, lifecycle scripts, and unexpected lockfile or dependency changes before adopting updates.
- Use lockfiles and controlled dependency updates to make changes visible and reproducible; a lockfile helps identify the version selected, but does not make a malicious selected version safe.
- Keep private registry and mirror behavior in view when evaluating alerts, because a package may have been cached or copied outside the public registry.
4. Isolate CI from untrusted code
- Avoid running code from untrusted forks in privileged workflow contexts.
- Limit which events and users can trigger workflows with secrets or write permissions.
- Separate validation jobs from release or publish jobs, and grant each workflow only the permissions it needs.
- Review cache write access as well as secret access; a workflow can create downstream risk even if it cannot directly publish a package.
5. Monitor and investigate with context
- Watch security advisories and review unexpected dependency or lockfile changes.
- When an alert names a package, establish the exact package version, where it was obtained, whether it ran, and which systems executed it.
- Check build systems, developer machines, private registries, and mirrors that may have consumed or retained the affected version.
- If a compromised install could access credentials, rotate the credentials that were exposed and review their use. GitHub’s security-incident guidance notes that supply-chain incidents can connect credential compromise, code injection, and exfiltration, and documents malware alerts for npm packages.
- Follow the package-specific advisory’s remediation rather than assuming every malicious version requires the same response.
What should you do if a package version is affected?
Containment depends on the package and payload. For the specific color@5.0.1 advisory, the listed patched version is 5.0.2, and the advisory recommends removing node_modules, cleaning the package-manager cache, rebuilding browser bundles, and purging compromised versions from private registries or mirrors. Those steps are specific to that advisory; do not treat them as a universal cleanup recipe for a different package.
For another incident, start with its current advisory and determine whether the affected version was installed or executed in an environment relevant to the payload. If credentials may have been accessible during installation or execution, investigate and rotate them; if a build system or registry mirror retained the version, include it in containment. Preserve enough incident detail to identify which projects and systems consumed the package before rebuilding or restoring them.
Recommended Free Tools
Best Value
- Beyond-fast WiFi 7 (802.11be) - WiFi 7 (802.11be) dual-band extendable router boosts speeds up to 3600 Mbps, with 4096-QAM increasing a single frequency band’s transmission speed by 1.2 times
- Unleashing Multi-link operation (MLO) for Ultra-Smooth Connectivity - Link to multiple bands at the same time to ensure stable internet connections and efficient data transfers
- Versatile WAN configuration options - Establish always-on internet through AI WAN detection and a convenient USB port ready for 4G LTE and 5G Mobile tethering.
- Smart Home Master - Easily establish up to three SSIDs with Smart Home Master for easy IoT device setup and management, instant VPN connections, and convenient parental controls.
- Commercial-Grade network security - Network security with commercial-grade AiProtection Pro powered by Trend Micro, plus a one-tap security scan and Safe Browsing.
How should teams evaluate package-security controls?
Do not judge a security product or process by a generic claim to “secure dependencies.” Compare what it actually covers and what evidence it provides:
- Attack stage: Does it address account access, publishing, CI, dependency resolution, runtime behavior, or only some of these?
- Prevention or detection: Does it block an action before publication or installation, or alert after a risky package or version is identified?
- Ecosystems and registries: Which package ecosystems, private registries, and mirrors does it support?
- Alert quality: Does an alert identify the package, version, behavior, and affected projects, and give actionable remediation?
- Workflow fit: Can developers review and resolve findings in the tools and update processes they already use?
- Incident response: Can teams determine where a package ran and which credentials or build systems may have been exposed?
npm says it scans packages for known malicious content, runs packages to identify behavioral patterns, and removes reported malicious content. npm also says it can detect and block typosquat packages but cannot detect dependency-confusion attacks. Those protections help with specific threats; they do not remove the need to verify dependencies, secure publishing accounts, or isolate workflows. GitHub likewise describes supply-chain attacks as chains of weaknesses addressed through layered controls. The available incident and product documentation does not establish a ranked vendor comparison or prove that one tool prevents every attack path.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

