Popular NPM packages with over one million downloads hit by malware


  • 17 NPM packages with more than one million weekly downloads were compromised to deliver a rat
  • The attack could turn into a larger supply chain attack, warned experts
  • The packages had since been printed but users should be on their guard

More than a dozen packages on NPM were poisoned with a remote access Trojan (Rotte), possibly infected millions of projects.

Cybersecurity scientists Aikido Security recently discovered malicious code buried very deeply in 17 popular gluestack packages.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top