As cited
Copy frozen at (site build).
Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond
A supply chain attack affected widely-used npm packages including debug and chalk, introducing a wallet-hijacking browser interceptor that remained undetected for approximately two hours. The incident achieved near-universal package prevalence with malware present in roughly ten percent of affected installations, and analysis reveals the attack's rapid propagation across the ecosystem.
Why it matters: JavaScript developers and organizations using npm dependencies face immediate exposure to wallet theft and browser interception if they installed affected versions of debug, chalk, or dependent packages during the attack window; urgent dependency audits and updates are required.
- Source published
- First seen by Cybersecurity Tracker