BR100 Increased By (1.49%)
BR30 Increased By (1.47%)
KSE100 Increased By (1.29%)
KSE30 Increased By (1.36%)
AGHA 7.88 Increased By ▲ 0.13 (1.68%)
BECO 5.23 Increased By ▲ 0.04 (0.77%)
BML 58.74 Increased By ▲ 0.08 (0.14%)
BOP 34.66 Increased By ▲ 0.97 (2.88%)
CNERGY 10.90 Increased By ▲ 0.29 (2.73%)
CSIL 5.43 Increased By ▲ 0.13 (2.45%)
FCCL 54.67 Increased By ▲ 0.93 (1.73%)
FFL 16.79 Increased By ▲ 0.33 (2%)
FNEL 1.23 Increased By ▲ 0.01 (0.82%)
KEL 7.45 Increased By ▲ 0.17 (2.34%)
KOSM 5.68 Increased By ▲ 0.04 (0.71%)
LOTCHEM 30.05 Increased By ▲ 0.40 (1.35%)
MLCF 97.44 Increased By ▲ 1.08 (1.12%)
NBP 206.70 Increased By ▲ 3.17 (1.56%)
NCPL 58.36 Increased By ▲ 1.51 (2.66%)
NPL 69.25 Increased By ▲ 1.94 (2.88%)
OGDC 321.90 Increased By ▲ 3.68 (1.16%)
PACE 10.79 Increased By ▲ 0.16 (1.51%)
PAEL 42.77 Increased By ▲ 1.00 (2.39%)
PIBTL 17.20 Increased By ▲ 0.39 (2.32%)
PPL 223.70 Increased By ▲ 3.53 (1.6%)
PRL 52.35 Increased By ▲ 3.30 (6.73%)
PTC 71.10 Increased By ▲ 1.09 (1.56%)
SSGC 29.64 Increased By ▲ 0.50 (1.72%)
TBL 9.87 Increased By ▲ 0.10 (1.02%)
TELE 8.97 Increased By ▲ 0.15 (1.7%)
TPL 17.48 Increased By ▲ 0.31 (1.81%)
TPLP 13.04 Increased By ▲ 0.53 (4.24%)
TREET 22.94 Increased By ▲ 0.35 (1.55%)
TRG 60.62 Increased By ▲ 0.40 (0.66%)

ISLAMABAD: A critical supply chain compromise has been disclosed in the npm JavaScript ecosystem, exposing enterprises worldwide to risks of cryptocurrency theft, credential leakage and unauthorized code execution.

This has been revealed in an advisory issued by the National Cyber Emergency Response Team of Pakistan (NCERT) and urged organizations to immediately upgrade to the latest fixed versions of all compromised npm packages.

The incident, reported on September 8, 2025, occurred after attackers compromised the credentials of maintainer Josh Junon (alias qix) and uploaded malicious versions of widely used packages. At least 18 popular libraries — including debug, chalk, ansi-styles, and strip-ansi — were affected. These malicious releases were automatically fetched by developers and CI/CD pipelines, significantly widening the scope of impact.

The injected code contained a browser-based cryptostealer payload designed to silently intercept cryptocurrency transactions, exfiltrate API keys and credentials, and redirect sensitive data. Exploitation required no user interaction beyond installation, making the attack low-complexity but high-impact.

Industry experts have assessed the compromise as critical, assigning it an estimated CVSS v3.1 score of 9.8. Indicators of compromise include outbound connections to attacker-controlled cryptocurrency wallets and abnormal credential harvesting activity from application logs.

With npm packages embedded in financial systems, e-commerce platforms, and enterprise applications, the compromise poses a material risk to business continuity and supply chain integrity. Analysts warn that compromised dependencies can propagate rapidly across downstream systems, potentially exposing corporate networks to systemic breaches.

The National CERT has urged organizations to rebuild and redeploy affected applications, rotate all credentials, tokens, and API keys exposed during the attack window, strengthen supply chain security by enforcing MFA for maintainer accounts, restricting unverified dependency updates, and monitoring pipelines for anomalies.

npm packages account for more than 2 billion weekly downloads globally. Experts note that Pakistan’s digital economy — increasingly dependent on open-source software — must adopt stronger safeguards to mitigate such systemic risks.

“This incident underscores the vulnerability of modern supply chains to upstream compromise,” the advisory stated, warning that failure to act promptly could result in long-term infiltration of enterprise systems.

Copyright Business Recorder, 2025

Comments

Comments are closed for this article.