A running record of confirmed npm supply chain attacks going back to 2018: what happened, which packages and versions were affected, and how early each one could realistically have been caught. This page exists because 0Day’s whole job is catching the next one before it reaches your repos, so we track every confirmed one that already has, most recent first.
NPMJune 17, 2026
Mastra AI npm Supply Chain Attack
A hijacked npm maintainer account with publish rights across the Mastra AI ecosystem was used to backdoor more than 140 packages. The poisoned releases pulled in easy-day-js, a malicious typosquat of the widely trusted dayjs library, which triggered an obfuscated dropper on install, before any application code ever imported it, disabled TLS certificate verification, and reached out to attacker-controlled infrastructure for a second-stage payload. Microsoft attributed the campaign with high confidence to Sapphire Sleet, a North Korean state-sponsored actor active since 2020, making this one of the clearest state-actor attributions yet for an npm compromise.
144 packages backdoored
DPRK-attributed (Sapphire Sleet)
Install-time trigger, no import required
Read the full writeup →
NPMJune 2026
Miasma: Red Hat npm Worm Attack
A self-propagating worm compromised 32 Red Hat npm packages via a Shai-Hulud-derived payload that harvested cloud credentials.
Read the full writeup →
NPMMay 2026
node-ipc npm Package Compromised
Three malicious versions of a foundational Node.js library were published carrying an identical credential-stealing payload.
Read the full writeup →
NPMMarch 2026
Axios npm Package Compromise
Axios, the JavaScript ecosystem’s most-downloaded HTTP client, was compromised and weaponized to deliver a cross-platform remote access trojan.
Read the full writeup →
NPMSeptember 2025
Shai-Hulud npm Worm
A self-propagating worm compromised maintainer npm tokens and spread through hundreds of packages, stealing GitHub and cloud credentials from every machine it touched.
Read the full writeup →
NPMAugust 2025
Nx “s1ngularity” npm Attack
A GitHub Actions injection let attackers steal an npm token and push malicious Nx packages that exfiltrated thousands of developer secrets.
Read the full writeup →
NPMNovember 2021
coa and rc npm Packages Compromised
Two widely used packages were hijacked days after ua-parser-js in a near-identical password-stealing attack.
Read the full writeup →
NPMOctober 2021
ua-parser-js npm Package Compromised
A hijacked maintainer account was used to publish cryptominer and credential-stealing malware for a four-hour window.
Read the full writeup →
NPMSeptember–November 2018
event-stream npm Attack: flatmap-stream Bitcoin Theft
A social-engineered maintainer handoff let an attacker slip a Bitcoin-wallet-stealing dependency into a package downloaded millions of times.
Read the full writeup →
NPMJuly 2018
eslint-scope npm Account Hijack
A compromised maintainer account was used to publish a malicious eslint-scope version that stole npm publish tokens from installers.
Read the full writeup →
Why we track this
Every incident on this page followed the same pattern: a maintainer account or a build pipeline was compromised, a trojanized version reached the registry, and the clock started running before most engineering teams had any idea their dependency tree was affected. 0Day’s pipeline is built to compress that window: signals from 20+ threat intelligence sources are corroborated and pushed to an org the moment a package and version it actually ships is implicated, often before an official advisory or CVE exists. See how that differs from a dependency scanner, or read the exact access 0Day needs to do this for a GitHub organization.
New incidents get added here as they’re confirmed. If you spot one that should be on this list, email support@0dayalerts.com.