Security Control Framework
GitLab discovers widespread npm supply chain attack

GitLab discovers widespread npm supply chain attack

11/24/2025 · Michael Henriksen

What this post added

This post details the discovery and technical analysis of a widespread npm supply chain attack involving a destructive malware variant. It outlines the malware's multi-stage infection vector, credential harvesting techniques (GitHub, npm, cloud), data exfiltration methods using attacker-controlled GitHub repositories, and its worm-like propagation mechanism within the npm ecosystem. A critical component is the 'dead man's switch' payload that triggers data destruction if the malware loses access to its infrastructure. The post also provides indicators of compromise and explains how GitLab's Dependency Scanning can help detect this campaign.

Read the original post ↗