image background

Critical NPM Security Alert: Major Supply Chain Attack Affects Packages with 2.6 Billion Weekly Downloads

What Happened On September 8, 2025, the JavaScript ecosystem experienced one of its largest supply chain attacks. Popular NPM packages with over 2.6 billion combined weekly downloads were compromised after a trusted maintainer’s account was hijacked through a phishing attack. The maintainer, known as “Qix”, posted on yCombinator “Hi, yep I got pwned. Sorry everyone, … Read more

Book a Discovery Call