npm: Coordinated Disclosure of 20 Malicious Packages in 16-Minute Burst
On October 1, 2026, 20 malicious npm packages were disclosed within a tight 16-minute window, revealing two distinct attack vectors: fresh malicious drops and older, potentially compromised packages.

Key findings
- 20 malicious npm packages disclosed on October 1, 2026.
- All advisories published within a tight 16-minute window.
- The burst includes both newly published malicious packages and older, potentially compromised ones.
- Older packages were first published 11 months prior, suggesting dormant malware or account compromise.
- All packages are rated with Critical severity, indicating full system compromise upon installation.
On October 1, 2026, a coordinated disclosure of 20 malicious npm packages occurred within a tight 16-minute window, from 03:31 UTC to 03:46 UTC. This rapid takedown event revealed two distinct categories of threats: newly published packages, likely typosquats or fresh malicious drops, and older packages that had been dormant for nearly a year before their malicious nature was identified and disclosed.
The burst comprised two main groups of packages. The first group, disclosed between 03:42 UTC and 03:46 UTC, consisted of seven packages such as my-ctf-helper-script-9921, pulse-pwn-9f3a2, and pf25262. These packages were all first published on the same day as their disclosure, suggesting they were fresh malicious uploads or typosquats designed for immediate impact. Their names appear somewhat arbitrary or themed, potentially targeting specific interests like 'CTF' (Capture The Flag) or using numerical suffixes.
The second, larger group of thirteen packages, including mms-service, mod-manager, and generator-epic-react, were all disclosed precisely at 03:31 UTC. A critical detail for this group is their first_published date of October 29, 2025 – nearly 11 months prior to their disclosure. This significant time gap, combined with the suspicious version 0.0.1-security across all these packages, strongly indicates a potential maintainer account compromise where malicious code was injected into existing, albeit low-download, packages, or that these were part of a long-term dormant campaign that was only recently detected.
The advisories for these packages uniformly categorize them as malicious, indicating severe compromise upon installation. However, the provided information does not detail specific behavioral findings from tools like OpenSSF Package Analysis, nor does it list any specific Indicators of Compromise (IOCs) such as command-and-control domains that might have been extracted from their malicious payloads.
All 20 disclosed packages are rated with Critical severity. This designation implies that any system that installed these malicious packages should be considered fully compromised. Such compromises typically grant attackers extensive control over the affected machine, allowing for data exfiltration, credential theft, or further propagation of malware. Users are advised to treat any system that has interacted with these packages as untrustworthy and take immediate remediation steps.
Developers should immediately audit their package-lock.json or yarn.lock files for any of the disclosed package names. If any are found, it is crucial to consider the affected environment compromised. Recommended response actions include:
- Rotating all credentials, tokens, and API keys that were accessible from the compromised environment.
- Scanning the system for any unauthorized changes or persistent malware.
- Reviewing npm token logs for any unauthorized publish events if you are a package maintainer.
A representative list of the malicious packages includes:
my-ctf-helper-script-9921pulse-pwn-9f3a2pf25262mms-servicemod-managergenerator-epic-reactssp-config-management-tool
This coordinated disclosure highlights the persistent and evolving threat landscape within public package registries like npm. The presence of both newly published malicious packages and older, potentially compromised ones within the same rapid takedown event underscores the multi-faceted nature of supply chain attacks. While some attackers rely on quick typosquatting for immediate impact, others may leverage compromised accounts to inject malware into existing packages, sometimes remaining undetected for extended periods. The swift, coordinated response to this burst demonstrates the ongoing efforts by security teams to identify and mitigate these threats, but also serves as a reminder for developers to maintain vigilance in their dependency management practices.