BR100 Increased By (1.02%)
BR30 Increased By (1.71%)
KSE100 Increased By (0.58%)
KSE30 Increased By (0.65%)
BECO 6.03 Increased By ▲ 0.26 (4.51%)
BML 52.61 Decreased By ▼ -0.39 (-0.74%)
BOP 34.23 Increased By ▲ 0.24 (0.71%)
CNERGY 8.16 Increased By ▲ 0.05 (0.62%)
DCL 12.23 Increased By ▲ 0.03 (0.25%)
FCCL 53.80 Increased By ▲ 0.97 (1.84%)
FCSC 5.24 Increased By ▲ 0.17 (3.35%)
FFL 18.03 Increased By ▲ 0.08 (0.45%)
FNEL 1.30 Increased By ▲ 0.01 (0.78%)
HUMNL 11.00 Increased By ▲ 0.12 (1.1%)
KEL 8.07 Increased By ▲ 0.05 (0.62%)
KOSM 5.39 Decreased By ▼ -0.13 (-2.36%)
MLCF 87.90 Increased By ▲ 1.39 (1.61%)
NBP 186.60 Increased By ▲ 1.44 (0.78%)
PACE 10.75 Increased By ▲ 0.17 (1.61%)
PAEL 39.95 Increased By ▲ 0.53 (1.34%)
PIAHCLA 26.19 Decreased By ▼ -0.03 (-0.11%)
PIBTL 17.32 Increased By ▲ 0.65 (3.9%)
PPL 233.49 Increased By ▲ 5.31 (2.33%)
PRL 34.98 Increased By ▲ 0.30 (0.87%)
PTC 67.71 Increased By ▲ 2.38 (3.64%)
SEARL 90.90 Increased By ▲ 0.77 (0.85%)
SSGC 27.20 Increased By ▲ 0.60 (2.26%)
TELE 8.57 Increased By ▲ 0.29 (3.5%)
THCCL 60.85 Increased By ▲ 2.35 (4.02%)
TPLP 8.78 Increased By ▲ 0.56 (6.81%)
TREET 24.65 Increased By ▲ 0.12 (0.49%)
TRG 71.50 Increased By ▲ 1.79 (2.57%)
WAVES 10.01 Increased By ▲ 0.07 (0.7%)
WTL 1.27 Decreased By ▼ -0.01 (-0.78%)

ISLAMABAD: A critical supply chain compromise has been disclosed in the npm JavaScript ecosystem, exposing enterprises worldwide to risks of cryptocurrency theft, credential leakage and unauthorized code execution.

This has been revealed in an advisory issued by the National Cyber Emergency Response Team of Pakistan (NCERT) and urged organizations to immediately upgrade to the latest fixed versions of all compromised npm packages.

The incident, reported on September 8, 2025, occurred after attackers compromised the credentials of maintainer Josh Junon (alias qix) and uploaded malicious versions of widely used packages. At least 18 popular libraries — including debug, chalk, ansi-styles, and strip-ansi — were affected. These malicious releases were automatically fetched by developers and CI/CD pipelines, significantly widening the scope of impact.

The injected code contained a browser-based cryptostealer payload designed to silently intercept cryptocurrency transactions, exfiltrate API keys and credentials, and redirect sensitive data. Exploitation required no user interaction beyond installation, making the attack low-complexity but high-impact.

Industry experts have assessed the compromise as critical, assigning it an estimated CVSS v3.1 score of 9.8. Indicators of compromise include outbound connections to attacker-controlled cryptocurrency wallets and abnormal credential harvesting activity from application logs.

With npm packages embedded in financial systems, e-commerce platforms, and enterprise applications, the compromise poses a material risk to business continuity and supply chain integrity. Analysts warn that compromised dependencies can propagate rapidly across downstream systems, potentially exposing corporate networks to systemic breaches.

The National CERT has urged organizations to rebuild and redeploy affected applications, rotate all credentials, tokens, and API keys exposed during the attack window, strengthen supply chain security by enforcing MFA for maintainer accounts, restricting unverified dependency updates, and monitoring pipelines for anomalies.

npm packages account for more than 2 billion weekly downloads globally. Experts note that Pakistan’s digital economy — increasingly dependent on open-source software — must adopt stronger safeguards to mitigate such systemic risks.

“This incident underscores the vulnerability of modern supply chains to upstream compromise,” the advisory stated, warning that failure to act promptly could result in long-term infiltration of enterprise systems.

Copyright Business Recorder, 2025

Comments

Comments are closed for this article.