npm: Seven Malicious Packages Disclosed in Coordinated 29-Minute Drop
On September 28, 2026, seven unique malicious npm packages were disclosed within a tight 29-minute window, indicating a coordinated attack targeting the software supply chain.

Key findings
- Seven unique malicious npm packages were disclosed on September 28, 2026.
- A total of 14 advisories were published within a 29-minute window, indicating a coordinated effort.
- Packages like
nebulaai-sdkandnebula-llmsuggest thematic impersonation. - All disclosed packages were rated with 'Critical' severity.
- Low download counts suggest fresh malicious uploads rather than maintainer takeovers.
On September 28, 2026, seven unique malicious packages were disclosed on the npm registry within a 29-minute window, from 18:02 UTC to 18:31 UTC. These packages, identified and removed from the registry, posed critical risks to developers who might have inadvertently installed them. The rapid succession of these disclosures, totaling 14 advisories for the 7 unique packages, points to a coordinated effort by threat actors to inject malicious code into the software supply chain.
While no single, overarching naming convention like a shared scope or prefix was observed across all packages, some exhibited thematic similarities, suggesting a targeted approach. For instance, nebulaai-sdk and nebula-llm appear to impersonate AI/LLM-related projects, while chalk-figlet and figlet-chalk-render mimic popular utility libraries. Other packages, such as simple-date-formatter-new-12, fabric-render-bridge, and fabric-asset-pipeline, also appeared during this rapid disclosure event. The low download counts for these packages, generally in the hundreds per week, suggest they were either fresh typosquats or newly introduced malicious uploads rather than compromises of long-established, highly popular projects.
The exact nature of the malicious behavior for these packages was not detailed in the provided advisories. However, the 'Critical' severity assigned to each disclosure strongly implies that they were designed to execute harmful actions upon installation. Typical malicious behaviors in such cases include remote code execution, credential harvesting, or establishing persistent backdoors on compromised systems.
The uniform 'Critical' severity rating across all disclosed packages underscores the severe potential impact on affected users. This classification means that any system where these malicious versions were installed should be considered fully compromised. Organizations and individual developers are strongly advised to treat such an incident with the utmost gravity, immediately isolating affected systems and rotating all sensitive credentials and secrets from a separate, secure machine to prevent further exploitation.
To mitigate potential risks, developers should immediately audit their project dependencies by inspecting package-lock.json or yarn.lock files for the presence of any of the disclosed malicious packages. If any of the following package names are identified, prompt action is required:
simple-date-formatter-new-12nebulaai-sdknebula-llmfiglet-chalk-renderfabric-render-bridgechalk-figletfabric-asset-pipeline
Upon detection, affected systems must be isolated, and all credentials associated with the development environment, including npm tokens, API keys, and other sensitive access tokens, should be revoked and regenerated from a clean environment. Additionally, reviewing security logs for any unauthorized activity originating from the compromised systems is a crucial step in incident response.
This rapid succession of disclosures within a short timeframe highlights the persistent and evolving threat of supply chain attacks targeting public package registries like npm. While the specific threat actors or their motivations behind this particular burst remain undisclosed, such coordinated drops underscore the critical need for continuous vigilance, automated security scanning, and robust security practices throughout the software development lifecycle to protect against similar future incursions.