npm Ecosystem
Incident posture
Linked entities
- Victim
- npm Ecosystem
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A supply-chain attack targeting a widely used JavaScript package manager compromised software packages distributed through the npm platform, exposing downstream developers and organizations to credential theft. The incident exploited the trust placed in the open-source ecosystem, allowing malicious code to be delivered into development environments and production systems that depended on the affected packages. By infiltrating packages commonly embedded in web and application development workflows, the threat actors gained potential access to sensitive credentials and internal systems across numerous organizations, amplifying the blast radius well beyond a single victim. The attack underscored the systemic risk posed by compromises in shared software supply chains, where a single intrusion can cascade across thousands of dependent projects and businesses globally.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The npm Ecosystem supply-chain attack was listed among the ten most significant cyber incidents of 2025 by Tokio Marine HCC International in its sixth consecutive annual cyber incidents report. The incident involved an IT software provider whose widely used JavaScript packages were compromised, exposing developers' and organisations' environments to credential theft. The attack was identified as one of several major technology supply-chain compromises during the year, a category that, along with ransomware and cloud infrastructure concentration, was cited as continuing to drive systemic cyber risk for organisations worldwide. The npm ecosystem compromise was recognised for its operational disruption and broader implications for the global digital ecosystem, though specific details about the timing of the compromise, the identity of the threat actor, and the precise method of intrusion were not elaborated upon in the source reporting.
The broader context of the year in cyber incidents saw this npm attack sit alongside other major events, including a ransomware incident affecting Marks & Spencer that caused an estimated £300 million impact to operating profit and triggered sector-wide effects as other major UK retailers such as Co-op and Harrods also experienced cyber incidents. A separate breach targeting Jaguar Land Rover was marked as the most economically damaging cyber incident to hit the UK, with the shutdown of vehicle production resulting in a £1.9 billion financial loss. A series of major outages affecting Amazon Web Services, Azure, and Cloudflare highlighted the systemic risk of cloud concentration and caused cascading service failures across SaaS organisations. The Salesforce / Drift OAuth large-scale data breach exploited compromised OAuth tokens to access hundreds of Salesforce customer environments, exposing records, contact details, and account information of millions of customers. An alleged supply-chain breach affecting Oracle Corporation Cloud Platform reportedly impacted over 140,000 tenants, with threat actors claiming the exfiltration of around six million records via a login endpoint.
Beyond these, the report documented an APT group that used Claude AI to carry out one of the first known AI-orchestrated cyberattacks at scale, with a state-sponsored cyber-espionage company automating 80-90% of a large-scale campaign targeting approximately 30 global organisations. SK Telecom suffered a cybersecurity breach detected in April that exposed the data of nearly 27 million users, creating widespread risk of SIM-cloning and identity theft, with attackers having maintained undetected access since June 2022. Kering Group experienced unauthorised access to internal systems, affecting fashion brands including Gucci, Balenciaga, and Alexander McQueen, and exposing personal information of millions of customers globally. Asahi Group Holdings was forced to suspend key operational systems in Japan following a detected cyberattack, causing widespread disruption to order processes and shipments. The npm Ecosystem supply-chain attack, as item five on this list, formed part of this landscape of escalating threats that prompted the report's authors to note how AI evolved from a theoretical risk to an active threat over the past year, and how the pace of change in cyber threats had accelerated significantly over the twelve months reviewed.
Sources
Sources available to members: 1 source.