Malware Injected Into Code Packages That Get 2 Billion+ Downloads Each Week

Published on September 8, 2025

An attack targeting the Node.js ecosystem was just identified — but not before it compromised 18 npm packages that account for billions of weekly downloads.