Sitemap

Massive NPM Supply Chain Attack: npm debug and chalk packages compromised

3 min readSep 9, 2025

On September 8, 2025, attackers compromised a high-profile maintainer via a phishing email sent from an address at the look-alike domain support@npmjs.help, then published malwared versions of popular dependencies relied on by the entire JavaScript ecosystem. Coverage confirms the phishing domain and the maintainer’s acknowledgment.

Press enter or click to view image in full size

The phishing email

The maintainer shared that he was compromised by the use of phishing, using this email coming from support [at] npmjs [dot] help :

Press enter or click to view image in full size

The result: malicious releases across packages that collectively see ~2.6–2.7B weekly downloads — an unusually broad blast radius.

Compromised npm Packages (sorted by downloads)

  • 📦 ansi-styles — ⚠️ 6.2.2 — 🔗 npm — 📉 371.41M/week
  • 📦 debug — ⚠️ 4.4.2 — 🔗 npm — 📉 357.60M/week
  • 📦 chalk — ⚠️ 5.6.1 — 🔗 npm — 📉 299.99M/week
  • 📦 supports-color — ⚠️ 10.2.1 — 🔗 npm — 📉 287.10M/week
  • 📦 strip-ansi — ⚠️ 7.1.1 — 🔗 npm — 📉 261.17M/week

--

--

Kristiyan Velkov
Kristiyan Velkov

Written by Kristiyan Velkov

Front-end Advocate | Meta Certified React JS Developer | Tech lead | Speaker | Book Author| React.js | Next.js | Angular | TS | DevOps | People management

No responses yet