In September 2025, attackers reportedly used a phishing campaign against npm maintainers to publish malicious versions of popular packages. The headline’s “20” is a reported count, not a reconciled total: Aikido’s initial analysis listed 18 packages, while The Hacker News’s list names 20 entries but repeats one version. The malicious code was described as targeting crypto and Web3 activity in visitors’ browsers; the reports do not establish that every installation caused a compromise or financial loss.
What happened in the September 2025 npm attack?
The Hacker News reported that maintainer Josh Junon, known as Qix, received an email impersonating npm support and asking him to reset two-factor authentication. The reported phishing page requested his username, password, and a two-factor token. The Hacker News characterized adversary-in-the-middle credential theft as likely; that mechanism was not independently confirmed in the other cited reporting. The Hacker News, September 9, 2025.
Aikido said its intelligence feed flagged suspicious npm releases starting September 8, 2025, at 13:16 UTC. Its initial set contained 18 packages and represented more than two billion combined weekly downloads at the time of its report. That is an incident-era estimate of package reach, not a current download total. Aikido Security’s analysis.
What did the malicious packages do?
Reports described obfuscated code that ran in a website visitor’s browser and interfered with crypto or Web3 interactions. It could intercept wallet or transaction requests and redirect destinations or approvals toward attacker-controlled accounts. That made people using crypto services on affected sites a potential target; it does not show that every affected package download led to a theft.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
The distinction matters: a compromised version in a dependency tree is evidence to investigate, not proof that a particular user visited an affected site, executed the code in a relevant context, or lost funds.
Which package versions were reported?
The list below reproduces the package names and versions in The Hacker News report. It contains 20 entries but lists supports-hyperlinks@4.1.1 twice. Aikido’s initial list has 18 packages and does not match every name in this report; StepSecurity’s list also differs. These sources therefore do not establish one reconciled, authoritative 20-package list. Check the exact version in your lockfile rather than treating a package name alone as proof of exposure.
| Package and version (The Hacker News list) | Package and version (The Hacker News list) |
|---|---|
ansi-regex@6.2.1 |
ansi-styles@6.2.2 |
backslash@0.2.1 |
chalk@5.6.1 |
chalk-template@1.1.1 |
color-convert@3.1.1 |
color-name@2.0.1 |
color-string@2.1.1 |
debug@4.4.2 |
error-ex@1.3.3 |
has-ansi@6.0.1 |
is-arrayish@0.3.3 |
proto-tinker-wc@1.8.7 |
supports-hyperlinks@4.1.1 |
simple-swizzle@0.2.3 |
slice-ansi@7.1.1 |
strip-ansi@7.1.1 |
supports-color@10.2.1 |
supports-hyperlinks@4.1.1 (repeated in the report) |
wrap-ansi@9.0.1 |
The project’s GitHub issue separately identifies debug@4.4.2 as compromised and marks the issue resolved. debug project issue #1005.
How large were the packages?
Aikido’s 2025 analysis reported the following weekly download figures for named packages. They describe the report’s incident-era measurements, not present-day registry counts.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems| Package | Weekly downloads reported by Aikido in 2025 |
|---|---|
ansi-styles |
371.41 million |
debug |
357.6 million |
supports-color |
287.1 million |
chalk |
299.99 million |
strip-ansi |
261.17 million |
ansi-regex |
243.64 million |
| All 18 packages in Aikido’s initial set | More than 2 billion combined |
How did the reported scope expand?
The Hacker News said the campaign later involved another maintainer and additional packages, including DuckDB-related packages and Prebid releases. Those reports concern later activity and should not be merged into the initial Qix-associated package set when checking versions or describing the attack’s first wave.
What should developers do if a project may be affected?
- Check resolved versions. Search the project’s lockfiles and dependency tree for the package-and-version pairs in the published lists. Include transitive dependencies, and distinguish an exact affected version from a package name that appears at a safe version.
- Establish whether the code ran. If an affected version was installed or executed, follow your incident-response process to identify when and where it ran, which applications or build jobs consumed it, and whether affected code could have reached users’ browsers.
- Assess exposed data and actions. Review the relevant application and build context for secrets or crypto wallet interactions that could have been accessible. A lockfile match alone does not demonstrate that funds were stolen.
- Apply your response procedure. Use your organization’s normal process to remove or replace affected releases, investigate possible credential or secret exposure, and document the scope. The available incident reports do not establish one universal remediation sequence for every project.
Junon apologized publicly, saying, “Sorry everyone, I should have paid more attention,” according to The Hacker News’s September 9, 2025 report. The Hacker News.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can teams reduce exposure to similar package attacks?
Controls can act at different stages, and they solve different problems. A cooldown or approval policy can slow adoption of a newly published dependency; CI runtime monitoring can flag unexpected behavior during a build; release and provenance monitoring can help spot suspicious publishing activity. None should be treated as a substitute for reviewing scope and responding to a confirmed incident.
- Before adoption: Consider a policy that delays or requires review of newly released dependencies. Evaluate which registries and package managers it covers, whether it blocks or merely alerts, and how exceptions are handled.
- During CI: Assess runtime monitoring for unexpected network access, file changes, or other suspicious build behavior. Check compatibility with your CI systems and the operational effort needed to investigate alerts.
- After publication: Review release and provenance monitoring for signals such as unusual maintainer or publishing changes. Confirm what evidence the tool provides and whether it can take action or only report.
StepSecurity discusses cooldown checks, CI runtime monitoring, and release monitoring as possible controls; these are vendor-described capabilities, not independent effectiveness findings for this incident. Aikido also points to Safe Chain as a related defense product. StepSecurity’s incident analysis; Aikido Security.
Best Value
When comparing controls, check the registries and build systems covered, whether a control blocks, alerts, or reports, and the cost and workload of operating it. The incident reporting does not establish a product ranking or independent test results.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

