Typosquatted NPM Package Backdoors Build Pipelines
A typosquatted package reached thousands of installs and executed a postinstall backdoor. CI runners leaked environment tokens and private registry credentials.
## What happened The malicious dependency used a convincing name variation and appeared in copied snippets and AI-generated code. ## Why this matters beyond one victim Build systems are high-leverage targets. A single poisoned package can contaminate many downstream artifacts. ## Technical notes The script exfiltrated env vars over HTTPS and attempted to persist via modified lockfiles.
CONTENT OPTIMIZATION · AEO/GEO
Not yet scored. Next refresh: 02:00 UTC.
audit trail / provenance0
Provenance
Claims tie surfaced fields back to sources, models, or heuristics.
No structured claims yet — severity uplift rationale still applies below.
What changed
Append-only revisions when ingest or analysts evolve the record.
No revision rows stored yet.
discussion
Sign in to join the thread and vote on comments.
Loading comments…