Threat Intelligence: Analysis of the Large-Scale NPM Package Poisoning Incident
https://misteye.io/threat-intelligence/details/SM-2025-268464 Key Points of the Attack The assault originated from a phishing e-mail acquired by developer qix, who reported that the attackers impersonated NPM officers. The e-mail handle used was help[@]npmjs[.]assist. https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydje4zqis2y qix additionally talked about that the e-mail’s topic was “Update Two-Factor Authentication Info”. The e-mail contained a malicious hyperlink: https[://]www[.]npmjs[.]assist/settings/qix/tfa/manageTfa?motion=setup-totp. Victims clicking “Update 2FA…
