BR100 Increased By (0.11%)
BR30 Decreased By (-0.26%)
KSE100 Increased By (0.12%)
KSE30 Increased By (0.09%)
AGHA 7.79 Increased By ▲ 0.04 (0.52%)
BECO 5.23 Increased By ▲ 0.04 (0.77%)
BML 57.26 Decreased By ▼ -1.40 (-2.39%)
BOP 34.10 Increased By ▲ 0.41 (1.22%)
CNERGY 9.92 Decreased By ▼ -0.69 (-6.5%)
CSIL 5.35 Increased By ▲ 0.05 (0.94%)
FCCL 54.61 Increased By ▲ 0.87 (1.62%)
FFL 16.70 Increased By ▲ 0.24 (1.46%)
FNEL 1.24 Increased By ▲ 0.02 (1.64%)
KEL 7.42 Increased By ▲ 0.14 (1.92%)
KOSM 5.75 Increased By ▲ 0.11 (1.95%)
LOTCHEM 29.35 Decreased By ▼ -0.30 (-1.01%)
MLCF 94.35 Decreased By ▼ -2.01 (-2.09%)
NBP 202.70 Decreased By ▼ -0.83 (-0.41%)
NCPL 57.00 Increased By ▲ 0.15 (0.26%)
NPL 67.78 Increased By ▲ 0.47 (0.7%)
OGDC 316.40 Decreased By ▼ -1.82 (-0.57%)
PACE 10.64 Increased By ▲ 0.01 (0.09%)
PAEL 43.15 Increased By ▲ 1.38 (3.3%)
PIBTL 16.72 Decreased By ▼ -0.09 (-0.54%)
PPL 220.50 Increased By ▲ 0.33 (0.15%)
PRL 49.05 No Change ▼ 0.00 (0%)
PTC 70.98 Increased By ▲ 0.97 (1.39%)
SSGC 28.17 Decreased By ▼ -0.97 (-3.33%)
TBL 9.90 Increased By ▲ 0.13 (1.33%)
TELE 8.80 Decreased By ▼ -0.02 (-0.23%)
TPL 18.14 Increased By ▲ 0.97 (5.65%)
TPLP 13.40 Increased By ▲ 0.89 (7.11%)
TREET 22.75 Increased By ▲ 0.16 (0.71%)
TRG 60.30 Increased By ▲ 0.08 (0.13%)

ISLAMABAD: A critical supply chain compromise has been disclosed in the npm JavaScript ecosystem, exposing enterprises worldwide to risks of cryptocurrency theft, credential leakage and unauthorized code execution.

This has been revealed in an advisory issued by the National Cyber Emergency Response Team of Pakistan (NCERT) and urged organizations to immediately upgrade to the latest fixed versions of all compromised npm packages.

The incident, reported on September 8, 2025, occurred after attackers compromised the credentials of maintainer Josh Junon (alias qix) and uploaded malicious versions of widely used packages. At least 18 popular libraries — including debug, chalk, ansi-styles, and strip-ansi — were affected. These malicious releases were automatically fetched by developers and CI/CD pipelines, significantly widening the scope of impact.

The injected code contained a browser-based cryptostealer payload designed to silently intercept cryptocurrency transactions, exfiltrate API keys and credentials, and redirect sensitive data. Exploitation required no user interaction beyond installation, making the attack low-complexity but high-impact.

Industry experts have assessed the compromise as critical, assigning it an estimated CVSS v3.1 score of 9.8. Indicators of compromise include outbound connections to attacker-controlled cryptocurrency wallets and abnormal credential harvesting activity from application logs.

With npm packages embedded in financial systems, e-commerce platforms, and enterprise applications, the compromise poses a material risk to business continuity and supply chain integrity. Analysts warn that compromised dependencies can propagate rapidly across downstream systems, potentially exposing corporate networks to systemic breaches.

The National CERT has urged organizations to rebuild and redeploy affected applications, rotate all credentials, tokens, and API keys exposed during the attack window, strengthen supply chain security by enforcing MFA for maintainer accounts, restricting unverified dependency updates, and monitoring pipelines for anomalies.

npm packages account for more than 2 billion weekly downloads globally. Experts note that Pakistan’s digital economy — increasingly dependent on open-source software — must adopt stronger safeguards to mitigate such systemic risks.

“This incident underscores the vulnerability of modern supply chains to upstream compromise,” the advisory stated, warning that failure to act promptly could result in long-term infiltration of enterprise systems.

Copyright Business Recorder, 2025

Comments

Comments are closed for this article.