The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →FortiGuard Labs reported in October 2023 that malicious npm packages used install scripts designed to collect sensitive developer and system data. SecurityWeek summarized the finding as 35 packages arranged in nine groups. The reports describe what the packages could collect and how they could transmit it; they do not establish how many people installed them or confirm losses at scale.
What Fortinet found in the 2023 npm incident
In its October 2, 2023 report, FortiGuard Labs described malicious packages hidden in npm, identified over several months and grouped by similarities in their code and behavior. Most used pre-install or post-install scripts: code npm can run as part of installing a package. SecurityWeek reported the finding the next day as 35 packages across nine groups (SecurityWeek’s October 3, 2023 summary).
Fortinet said the packages were designed to leak credentials, sensitive information, and source code. That describes researcher findings about package behavior and intent, not proof that every package successfully stole data from an installed system. The reports do not provide a confirmed victim count or an aggregate measure of losses.
What the packages tried to collect and how they sent it
The nine groups used different scripts and transfer methods. Fortinet’s report describes the following behaviors; the exact package names, affected versions, and hashes are in the original report.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
| Group | Reported behavior |
|---|---|
| 1 | An obfuscated index.js script could collect Kubernetes configuration, SSH keys, and other sensitive information, as well as the username, IP address, and hostname. |
| 2 | Scripts searched for selected files and directories, including source code and configuration files, archived them, and uploaded the archives to an FTP server. |
| 3–4 | index.mjs scripts used Discord webhooks to send sensitive information such as system details, usernames, and folder contents. |
| 5 | A webhook transmitted host and username information and home-directory contents. |
| 6 | Install scripts were described as exfiltrating information; the summary does not specify a more precise collection or transfer method. |
| 7 | An installer set NODE_TLS_REJECT_UNAUTHORIZED to 0, disabling TLS certificate validation and potentially exposing connections to man-in-the-middle attacks. |
| 8 | The package automatically downloaded and executed a potentially malicious executable. |
| 9 | A script collected system information, including the public IP address, and sent it to a Discord webhook. |
Fortinet’s report names examples including @expue/webpack 0.0.3-alpha.0, binarium-crm 1.0.0/1.0.9/1.9.9, @zola-helpers/client 1.0.1/1.0.2/1.0.3, @cima/prism-utils 23.2.1/23.2.2, and evernote-thrift 1.9.99. Treat package identity and version as a pair when checking for exposure: consult the complete package, version, and hash lists in Fortinet’s report rather than inferring that every version of a named package is affected.
How to check a project for a reported package
- Review the dependency declarations. Check
package.jsonfor the exact package names listed in Fortinet’s report. - Review the lockfile as well. Check the project’s npm lockfile for matching package names and versions. A dependency may be present in the resolved dependency tree even when it is not obvious from a quick review of the top-level declarations.
- Verify the exact pairing. Compare both the package name and resolved version with Fortinet’s indicators; don’t assume that an unlisted version is affected or that a similar-looking name is the same package.
- If you find a match, follow your organization’s incident-response process. Preserve relevant project and environment information and involve the team responsible for security. Removing a dependency can stop its use in a project, but by itself cannot undo possible disclosure of credentials or files.
The reports do not provide current npm registry status for these packages or a complete remediation playbook. A historical match is a reason to investigate, not evidence on its own that a particular system was compromised.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Controls that can reduce malicious dependency risk
Dependency checks, acquisition controls, and package-analysis tools address different points in the workflow. None is a guarantee, and the cited sources do not provide independent effectiveness measurements or a head-to-head comparison.
| Control | Where it helps | Limit to keep in mind |
|---|---|---|
| Review dependency declarations and lockfiles | Helps developers or responders identify suspicious direct and resolved dependencies in a project, including exact package and version matches. | It depends on reviewing the relevant project files and recognizing the indicator; it does not itself prevent a package from being acquired or reverse prior exposure. |
| Proxy registry or package allowlist | Can restrict which packages developers and build systems are able to acquire, before installation. | Rules need maintenance and must fit development and CI workflows. The sources do not quantify how effectively a specific policy would block these packages. |
| SCA or package-analysis tooling | Can inspect project dependencies and surface package-risk evidence within developer or CI workflows. | Coverage and findings depend on the tool and configuration. Fortinet says its FortiDevSec SCA scanner detects malicious packages used in project dependencies; that is Fortinet’s product claim, not an independent evaluation. |
| Developer awareness | Helps teams notice typosquatting, package impersonation, and suspicious install scripts when choosing dependencies. | Training complements technical controls; it cannot guarantee every malicious package will be recognized. |
Socket’s May 2, 2025 report on a separate npm campaign describes packages imitating familiar Python, Java, C++, .NET, and Node.js libraries, with shared infrastructure and obfuscated payloads. It illustrates that package impersonation remains a supply-chain risk, but it is distinct from Fortinet’s 2023 findings; the reports do not establish common attribution. Socket recommends auditing recent dependencies, considering a proxy registry or allowlist, and training developers to spot impersonation.
Recommended Free Tools
Fortinet also said FortiGuard Web Filtering detects the download URLs cited in its 2023 report. That, like its FortiDevSec detection statement, is a claim by the vendor about its own products rather than an independent product assessment.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

