npm debug / chalk Supply Chain Attack (September 2025)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3XczqR…U2zRSummary
On September 8, 2025, attackers compromised the npm account of open-source maintainer Josh Junon (alias 'qix') through a phishing campaign using the spoofed domain npmjs.help, then published malicious versions of 18 foundational JavaScript packages — including chalk (~300M weekly downloads) and debug (~357M) — that collectively exceeded 2 billion weekly downloads. The injected payload functioned as a browser-side wallet-draining cryptostealer, silently intercepting and rewriting cryptocurrency transaction destinations before signing. The malicious versions were available for approximately 7 hours before full removal; a second wave on September 9 targeted DuckDB npm accounts through the same phishing infrastructure.
Connected Entities
7 entities · 60 linked investigations- 191111…1111→mentioned with→npm debug / chalk Supply Chain Attack (September 2025)(50%)
- Ethereum→mentioned with→Bitcoin(60%)
- Litecoin→mentioned with→Bitcoin(70%)
- npm debug / chalk Supply Chain Attack (September 2025)→mentioned with→Bitcoin Cash(80%)
- Solana→mentioned with→Ethereum(60%)
- npm debug / chalk Supply Chain Attack (September 2025)→mentioned with→Litecoin(60%)
- npm debug / chalk Supply Chain Attack (September 2025)→mentioned with→Bitcoin(60%)
- Bitcoin Cash→mentioned with→Bitcoin(70%)
- npm debug / chalk Supply Chain Attack (September 2025)→mentioned with→Ethereum(80%)
- npm debug / chalk Supply Chain Attack (September 2025)→mentioned with→Solana(80%)
Timeline(12 events)
5 September 2025
Attackers register phishing domain npmjs.help, designed as a pixel-perfect replica of the npmjs.com website.
Sygnia Threat Report8 September 2025
13:00 UTC: Phishing email sent to chalk maintainer Josh Junon (qix) impersonating npm security personnel, claiming a 2FA compliance requirement with a 48-hour lockout deadline.
Sygnia Threat Report8 September 2025
13:16 UTC: First malicious package version published to npm, approximately 16 minutes after the AiTM phishing attack captured the maintainer's credentials and live 2FA token.
Sygnia Threat Report8 September 2025
Attacker publishes malicious versions of 18 npm packages including chalk, debug, ansi-styles, supports-color, strip-ansi, and 13 other foundational JavaScript utilities, injecting a browser-side cryptocurrency wallet-draining payload.
The Hacker News8 September 2025
14:16 UTC: Community member raises suspicions on Bluesky; user 'informatic' identifies that malicious npm versions are absent from the GitHub repository. Aikido Security credited for early detection.
Sygnia Threat Report8 September 2025
15:15 UTC: Maintainer Josh Junon publicly acknowledges the account breach.
Sygnia Threat Report8 September 2025
17:17 UTC: npm confirms the breach and initiates formal takedown of malicious package versions.
Sygnia Threat Report8 September 2025
17:39 UTC: Vercel activates incident response, identifies 70 Vercel teams with builds containing compromised package versions across 76 unique projects.
Vercel Blog8 September 2025
19:59 UTC: All impacted first-wave package versions removed from npm registry, approximately 7 hours after initial account compromise.
Sygnia Threat Report8 September 2025
22:19 UTC: Vercel completes purge of build caches for all 76 affected projects and issues customer notifications.
Vercel Blog9 September 2025
~01:11-01:13 UTC: Second wave begins. The duckdb_admin npm account is compromised via the same npmjs.help phishing infrastructure. Malicious versions of duckdb (1.3.3), @duckdb/duckdb-wasm (1.29.2), @duckdb/node-api (1.3.3), and @duckdb/node-bindings (1.3.3) published, containing identical wallet-drainer malware. Prebid and @coveops/abi also affected.
Socket.dev9 September 2025
DuckDB maintainers confirm compromise via the same phishing email used in the September 8 attack. GitHub security advisory GHSA-w62p-hx95-gf2c published for affected DuckDB packages.
DuckDB GitHub Security AdvisoryDecision Log
- hash: BQsCak1BPxDzm6PDCyr6KLYDgQR1Dv2YE8qhvQnhgFdA
This investigation is cryptographically anchored to the Solana blockchain (1 event). 11 of 11 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/20/2026, 12:11:26 PM
last updated: 7/27/2026, 2:04:32 AM
4 viewsavoid.net — verified advice for a post-truth world