• Latest
  • Trending
  • All
Software packages with more than 2 billion weekly downloads hit in supply-chain attack

Software packages with more than 2 billion weekly downloads hit in supply-chain attack

8 months ago
In UP chessboard, SP’s latest move: Women-led push to breach BJP allies’ base | Political Pulse News

In UP chessboard, SP’s latest move: Women-led push to breach BJP allies’ base | Political Pulse News

3 hours ago
Mamata Banerjee walks off stage at Bengal’s Bhabanipur rally, blames BJP for disruption

Mamata Banerjee walks off stage at Bengal’s Bhabanipur rally, blames BJP for disruption

4 hours ago
Engine fire on SWISS Delhi-Zurich flight during take off roll; aircraft evacuated on runway | India News

Engine fire on SWISS Delhi-Zurich flight during take off roll; aircraft evacuated on runway | India News

9 hours ago
UP Home Guard exam: Driven by hope and resilience, job seekers throng centres

UP Home Guard exam: Driven by hope and resilience, job seekers throng centres

12 hours ago
Ramdas Athawale says his party will contest 25 seats in Uttar Pradesh, ready to go solo if BJP disagrees

Ramdas Athawale says his party will contest 25 seats in Uttar Pradesh, ready to go solo if BJP disagrees

12 hours ago
BYD’s next all-electric hypercar is a convertible that’s coming to Europe first

BYD’s next all-electric hypercar is a convertible that’s coming to Europe first

12 hours ago
We dropped few too many catches: RR skipper Riyan Parag

We dropped few too many catches: RR skipper Riyan Parag

17 hours ago
Raghav Chadha revolt jolts AAP, raises questions on Kejriwal’s leadership and party’s future

Raghav Chadha revolt jolts AAP, raises questions on Kejriwal’s leadership and party’s future

17 hours ago
Labourer dies after huge chunk of soil falls on him during pipeline repair work in Aligarh

Labourer dies after huge chunk of soil falls on him during pipeline repair work in Aligarh

18 hours ago
Siddharth Nigam Opens Up On Struggling With His On-Screen Image

Siddharth Nigam Opens Up On Struggling With His On-Screen Image

18 hours ago
Delhi Road Accident: Overspeeding Tempo Kills Teenager In Shalimar Bagh

Delhi Road Accident: Overspeeding Tempo Kills Teenager In Shalimar Bagh

19 hours ago
Allahabad HC slams UP Police for chasing young couples, not probing crimes

Allahabad HC slams UP Police for chasing young couples, not probing crimes

19 hours ago
Sunday, April 26, 2026
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
  • Game
India News Online
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
    • All
    • Hindi Songs
    • Punjabi Songs
    इंस्टाग्राम वाली बीबी😃90’S Old Hindi Songs🤣90s Love Song😍Udit Narayan,Alka Yagnik,Kumar Sanu song

    इंस्टाग्राम वाली बीबी😃90’S Old Hindi Songs🤣90s Love Song😍Udit Narayan,Alka Yagnik,Kumar Sanu song

    इंसानियत 😃90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar Sanu songs

    इंसानियत 😃90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar Sanu songs

    Kheti | Hardev Mahinangal | Amnindr Bhangu | Latest Punjabi Songs 2026 | Lipci | Mukaam records

    Kheti | Hardev Mahinangal | Amnindr Bhangu | Latest Punjabi Songs 2026 | Lipci | Mukaam records

    PANGA (Official Video) | Labh Heera | Jaskaran Grewal | New Punjabi Songs 2026 |Latest Punjabi Songs

    PANGA (Official Video) | Labh Heera | Jaskaran Grewal | New Punjabi Songs 2026 |Latest Punjabi Songs

    Asla – Watan Sahi [Official MV] Latest Punjabi Song – K Million Music

    Asla – Watan Sahi [Official MV] Latest Punjabi Song – K Million Music

    Game – Surjit Bhullar | Mista Baaz | Bittu Cheema | Latest Punjabi Song 2026

    Game – Surjit Bhullar | Mista Baaz | Bittu Cheema | Latest Punjabi Song 2026

    Latest Punjabi Hit Songs 💞 Top Punjabi Songs Collection ✨ #punjabisongs #punjabimusic

    Latest Punjabi Hit Songs 💞 Top Punjabi Songs Collection ✨ #punjabisongs #punjabimusic

    Udaariyaan 💗🫠 ~ Satinder Sartaj | Punjabi song | #song #shorts #lyrics

    Udaariyaan 💗🫠 ~ Satinder Sartaj | Punjabi song | #song #shorts #lyrics

    Diljit Dosanjh : Dealer (Official Music Video) Virk Andaaz : Da Future

    Diljit Dosanjh : Dealer (Official Music Video) Virk Andaaz : Da Future

  • Travel
  • Game
No Result
View All Result
India News
No Result
View All Result
Home Technology

Software packages with more than 2 billion weekly downloads hit in supply-chain attack

by India News Online Team
September 9, 2025
in Technology
0
Software packages with more than 2 billion weekly downloads hit in supply-chain attack
Share on FacebookShare on TwitterShare on Email



Software packages with more than 2 billion weekly downloads hit in supply-chain attack

Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to be the world’s biggest supply-chain attack ever.

The attack, which compromised nearly two dozen packages hosted on the npm repository, came to public notice on Monday in social media posts. Around the same time, Josh Junon, a maintainer or co-maintainer of the affected packages, said he had been “pwned” after falling for an email that claimed his account on the platform would be closed unless he logged into a site and updated his two-factor authentication credentials.

Defeating 2FA the easy way

“Sorry everyone, I should have paid more attention,” Junon, who uses the moniker Qix, wrote. “Not like me; have had a stressful week. Will work to get this cleaned up.”

The unknown attackers behind the account compromise wasted no time capitalizing on it. Within an hour’s time, dozens of open source packages Junon oversees had received updates that added malicious code for transferring cryptocurrency payments to attacker-controlled wallets. With more than 280 lines of code, the addition worked by monitoring infected systems for cryptocurrency transactions and chaining the addresses of wallets receiving payments to those controlled by the attacker.

The packages that were compromised, which at last count numbered 20, included some of the most foundational code driving the JavaScript ecosystem. They are used outright and also have thousands of dependents, meaning other npm packages that don’t work unless they are also installed. (npm is the official code repository for JavaScript files.)

“The overlap with such high-profile projects significantly increases the blast radius of this incident,” researchers from security firm Socket said. “By compromising Qix, the attackers gained the ability to push malicious versions of packages that are indirectly depended on by countless applications, libraries, and frameworks.”

The researchers added: “Given the scope and the selection of packages impacted, this appears to be a targeted attack designed to maximize reach across the ecosystem.”

The email message Junon fell for came from an email address at support.npmjs.help, a domain created three days ago to mimic the official npmjs.com used by npm. It said Junon’s account would be closed unless he updated information related to his 2FA—which requires users to present a physical security key or supply a one-time passcode provided by an authenticator app in addition to a password when logging in.



Source link

Tags: attackBillionDownloadsHitpackagessoftwaresupplychainWeekly
Share197Tweet123Send

Related Posts

BYD’s next all-electric hypercar is a convertible that’s coming to Europe first
Technology

BYD’s next all-electric hypercar is a convertible that’s coming to Europe first

April 25, 2026
Lachy Groom to back India startup Pronto at a 0M valuation, sources say
Technology

Lachy Groom to back India startup Pronto at a $200M valuation, sources say

April 25, 2026
Google will invest as much as  billion in Anthropic
Technology

Google will invest as much as $40 billion in Anthropic

April 24, 2026
Huawei plans to spend up to .7B over five years to boost compute for training and testing autonomous cars, with ~.64B for autonomous driving R&D in 2026 (Daniel Ren/South China Morning Post)
Technology

Huawei plans to spend up to $11.7B over five years to boost compute for training and testing autonomous cars, with ~$2.64B for autonomous driving R&D in 2026 (Daniel Ren/South China Morning Post)

April 24, 2026
Load More
  • Trending
  • Comments
  • Latest
9 Festivals to Celebratein August in India

9 Festivals to Celebratein August in India

August 8, 2025
Corruption cases against govt officials: SC bats for striking balance | Latest News India

Corruption cases against govt officials: SC bats for striking balance | Latest News India

August 5, 2025
Guru Randhawa – SIRRA ( Official Video )

Guru Randhawa – SIRRA ( Official Video )

July 1, 2025
In UP chessboard, SP’s latest move: Women-led push to breach BJP allies’ base | Political Pulse News

In UP chessboard, SP’s latest move: Women-led push to breach BJP allies’ base | Political Pulse News

0
Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

0
Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

0
In UP chessboard, SP’s latest move: Women-led push to breach BJP allies’ base | Political Pulse News

In UP chessboard, SP’s latest move: Women-led push to breach BJP allies’ base | Political Pulse News

April 26, 2026
Mamata Banerjee walks off stage at Bengal’s Bhabanipur rally, blames BJP for disruption

Mamata Banerjee walks off stage at Bengal’s Bhabanipur rally, blames BJP for disruption

April 26, 2026
Engine fire on SWISS Delhi-Zurich flight during take off roll; aircraft evacuated on runway | India News

Engine fire on SWISS Delhi-Zurich flight during take off roll; aircraft evacuated on runway | India News

April 26, 2026
India News Online

24x7 Online News From India
India News Online is your news, entertainment, music fashion website. We provide you with the latest breaking news and videos straight from the entertainment industry.

Categories

  • Business
  • Entertainment
  • Health
  • Hindi News
  • Hindi Songs
  • India
  • International
  • Lifestyle
  • Panjab
  • Politics
  • Punjabi Songs
  • Sports
  • Technology
  • Travel
  • Uncategorized
No Result
View All Result

Recent Posts

  • In UP chessboard, SP’s latest move: Women-led push to breach BJP allies’ base | Political Pulse News
  • Mamata Banerjee walks off stage at Bengal’s Bhabanipur rally, blames BJP for disruption
  • Engine fire on SWISS Delhi-Zurich flight during take off roll; aircraft evacuated on runway | India News
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact

Copyright © 2021 - India News Online.

No Result
View All Result
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
  • Travel
  • Game

Copyright © 2021 - India News Online.