Skip to main content


A bunch of packages published by qix in NPM just got backdoored it looks like. Obfuscated code was added like two hours ago. #threatintel #npm

Gidi Kroon reshared this.

in reply to derekheld

For example: npmjs.com/package/is-arrayish?…

I think quite a few packages are impacted, potentially some very high volume ones. I gotta hop on a subway to make a plane though so it’s going to be hard for me to keep digging.

#threatintel #npm

This entry was edited (2 months ago)
in reply to Cat 🐈πŸ₯— (D.Burch) :blobcatrainbow:

most of the credit goes to the dev who reached out to me saying things seemed off. Don’t think I can name for confidentiality reasons unfortunately.
This entry was edited (2 months ago)
⇧