• Latest
  • Trending
  • All
Software packages with more than 2 billion weekly downloads hit in supply-chain attack

Software packages with more than 2 billion weekly downloads hit in supply-chain attack

9 months ago
First Somvati Amavasya Of The Year Could Bring New Job, More Money, Career Growth For These 4 Zodiac Signs

First Somvati Amavasya Of The Year Could Bring New Job, More Money, Career Growth For These 4 Zodiac Signs

2 hours ago
India is country of innovation, says France President Macron at Bharat Innovates event

India is country of innovation, says France President Macron at Bharat Innovates event

3 hours ago
National Stock Exchange IPO: Draft Papers Expected Next Week, Reviving Listing Plans

National Stock Exchange IPO: Draft Papers Expected Next Week, Reviving Listing Plans

4 hours ago
Lack of coordination in handling Nipah outbreak, alleges Leader of the Opposition Pinarayi Vijayan

Lack of coordination in handling Nipah outbreak, alleges Leader of the Opposition Pinarayi Vijayan

4 hours ago
PM Modi and Trump to Hold Key Bilateral Meeting on June 17 During G7 Summit

PM Modi and Trump to Hold Key Bilateral Meeting on June 17 During G7 Summit

6 hours ago
UP: Woman alleges deception in relationship, pressure to convert; one arrested

UP: Woman alleges deception in relationship, pressure to convert; one arrested

7 hours ago
Starmer to Meet Japan’s Takaichi as Fighter Jet Funding Sputters

Starmer to Meet Japan’s Takaichi as Fighter Jet Funding Sputters

8 hours ago
‘His Mask & Wig Both Come Off’: Mahua Moitra Slams TMC MP Sudip Bandyopadhyay Over BJP Meeting In Delhi | India News

‘His Mask & Wig Both Come Off’: Mahua Moitra Slams TMC MP Sudip Bandyopadhyay Over BJP Meeting In Delhi | India News

9 hours ago
FIFA World Cup 2026 Points Table And Team Standings

FIFA World Cup 2026 Points Table And Team Standings

10 hours ago
Yogi condemns remarks against Akhilesh Yadav’s daughter

Yogi condemns remarks against Akhilesh Yadav’s daughter

13 hours ago
‘All we got to bury was a DNA sample’: British victim’s mother seeks answers a year after Air India crash | Ahmedabad News

‘All we got to bury was a DNA sample’: British victim’s mother seeks answers a year after Air India crash | Ahmedabad News

15 hours ago
Will not allow illegal oil shipments from Iran, U.S. tells India

Will not allow illegal oil shipments from Iran, U.S. tells India

18 hours ago
Sunday, June 14, 2026
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
  • Game
India News Online
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
    • All
    • Hindi Songs
    • Punjabi Songs
    पियवा किसनवा 90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi

    पियवा किसनवा 90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi

    Sadabahar Hindi Songs Collection | 90s Hits Hindi Song |90s Evergreen Hindi Love Songs Audio Jukebox

    Sadabahar Hindi Songs Collection | 90s Hits Hindi Song |90s Evergreen Hindi Love Songs Audio Jukebox

    90s Bollywood Wedding Songs | Evergreen Bollywood Hits | Shadi Song | Sadabahar Hindi Songs Jukebox

    90s Bollywood Wedding Songs | Evergreen Bollywood Hits | Shadi Song | Sadabahar Hindi Songs Jukebox

    आज तो बाल बाल बच गया😄90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu song

    आज तो बाल बाल बच गया😄90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu song

    भाभी ने बचाई ननद की जान 😆 90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar

    भाभी ने बचाई ननद की जान 😆 90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar

    When Online Love Becomes Real💞Chinese mix Hindi Songs💞Cin Klip💞Chinese Drama💞Korean Mix Hindi Songs

    When Online Love Becomes Real💞Chinese mix Hindi Songs💞Cin Klip💞Chinese Drama💞Korean Mix Hindi Songs

    Cold Rude boy falling for cute girl 💕 korean mix hindi songs 💞 Chinese mix hindi songs

    Cold Rude boy falling for cute girl 💕 korean mix hindi songs 💞 Chinese mix hindi songs

    90s हिंदी सदाबहार गीत | 90’s Romantic Hindi Songs | 90’s सदाबहार फिल्मी गाने | 90’s Bollywood Songs

    90s हिंदी सदाबहार गीत | 90’s Romantic Hindi Songs | 90’s सदाबहार फिल्मी गाने | 90’s Bollywood Songs

    90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi Jukebox

    90’S Old Hindi Songs🥰 90s Love Song😍 Udit Narayan, Alka Yagnik, Kumar Sanu songs Hindi Jukebox

  • Travel
  • Game
No Result
View All Result
India News
No Result
View All Result
Home Technology

Software packages with more than 2 billion weekly downloads hit in supply-chain attack

by India News Online Team
September 9, 2025
in Technology
0
Software packages with more than 2 billion weekly downloads hit in supply-chain attack
Share on FacebookShare on TwitterShare on Email



Software packages with more than 2 billion weekly downloads hit in supply-chain attack

Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to be the world’s biggest supply-chain attack ever.

The attack, which compromised nearly two dozen packages hosted on the npm repository, came to public notice on Monday in social media posts. Around the same time, Josh Junon, a maintainer or co-maintainer of the affected packages, said he had been “pwned” after falling for an email that claimed his account on the platform would be closed unless he logged into a site and updated his two-factor authentication credentials.

Defeating 2FA the easy way

“Sorry everyone, I should have paid more attention,” Junon, who uses the moniker Qix, wrote. “Not like me; have had a stressful week. Will work to get this cleaned up.”

The unknown attackers behind the account compromise wasted no time capitalizing on it. Within an hour’s time, dozens of open source packages Junon oversees had received updates that added malicious code for transferring cryptocurrency payments to attacker-controlled wallets. With more than 280 lines of code, the addition worked by monitoring infected systems for cryptocurrency transactions and chaining the addresses of wallets receiving payments to those controlled by the attacker.

The packages that were compromised, which at last count numbered 20, included some of the most foundational code driving the JavaScript ecosystem. They are used outright and also have thousands of dependents, meaning other npm packages that don’t work unless they are also installed. (npm is the official code repository for JavaScript files.)

“The overlap with such high-profile projects significantly increases the blast radius of this incident,” researchers from security firm Socket said. “By compromising Qix, the attackers gained the ability to push malicious versions of packages that are indirectly depended on by countless applications, libraries, and frameworks.”

The researchers added: “Given the scope and the selection of packages impacted, this appears to be a targeted attack designed to maximize reach across the ecosystem.”

The email message Junon fell for came from an email address at support.npmjs.help, a domain created three days ago to mimic the official npmjs.com used by npm. It said Junon’s account would be closed unless he updated information related to his 2FA—which requires users to present a physical security key or supply a one-time passcode provided by an authenticator app in addition to a password when logging in.



Source link

Tags: attackBillionDownloadsHitpackagessoftwaresupplychainWeekly
Share197Tweet123Send

Related Posts

Yogi condemns remarks against Akhilesh Yadav’s daughter
Technology

Yogi condemns remarks against Akhilesh Yadav’s daughter

June 14, 2026
Best Air Fryer & Sandwich Maker Combos Under ₹7,000 | Tech News
Technology

Best Air Fryer & Sandwich Maker Combos Under ₹7,000 | Tech News

June 13, 2026
DoJ Approves Paramount Skydance-Warner Bros. Deal, Cementing Ellison Family Control Of American Media
Technology

DoJ Approves Paramount Skydance-Warner Bros. Deal, Cementing Ellison Family Control Of American Media

June 12, 2026
SpaceX IPO: Everything you need to know
Technology

SpaceX IPO: Everything you need to know

June 12, 2026
Load More
  • Trending
  • Comments
  • Latest
9 Festivals to Celebratein August in India

9 Festivals to Celebratein August in India

August 8, 2025
Corruption cases against govt officials: SC bats for striking balance | Latest News India

Corruption cases against govt officials: SC bats for striking balance | Latest News India

August 5, 2025
Guru Randhawa – SIRRA ( Official Video )

Guru Randhawa – SIRRA ( Official Video )

July 1, 2025
Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

0
Phool Maangu Na Bahaar Maangu – Video Song | Raja | Madhuri Dixit & Sanjay Kapoor

Phool Maangu Na Bahaar Maangu – Video Song | Raja | Madhuri Dixit & Sanjay Kapoor

0
Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

0
First Somvati Amavasya Of The Year Could Bring New Job, More Money, Career Growth For These 4 Zodiac Signs

First Somvati Amavasya Of The Year Could Bring New Job, More Money, Career Growth For These 4 Zodiac Signs

June 14, 2026
India is country of innovation, says France President Macron at Bharat Innovates event

India is country of innovation, says France President Macron at Bharat Innovates event

June 14, 2026
National Stock Exchange IPO: Draft Papers Expected Next Week, Reviving Listing Plans

National Stock Exchange IPO: Draft Papers Expected Next Week, Reviving Listing Plans

June 14, 2026
India News Online

24x7 Online News From India
India News Online is your news, entertainment, music fashion website. We provide you with the latest breaking news and videos straight from the entertainment industry.

Categories

  • Business
  • Entertainment
  • Health
  • Hindi News
  • Hindi Songs
  • India
  • International
  • Lifestyle
  • Panjab
  • Politics
  • Punjabi Songs
  • Sports
  • Technology
  • Travel
  • Uncategorized
No Result
View All Result

Recent Posts

  • First Somvati Amavasya Of The Year Could Bring New Job, More Money, Career Growth For These 4 Zodiac Signs
  • India is country of innovation, says France President Macron at Bharat Innovates event
  • National Stock Exchange IPO: Draft Papers Expected Next Week, Reviving Listing Plans
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact

Copyright © 2021 - India News Online.

No Result
View All Result
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
  • Travel
  • Game

Copyright © 2021 - India News Online.