BlogsVercelnpm Supply Chain Security

npm Supply Chain Security

npm Supply Chain Security

1
posts
2025

Vercel's platform demonstrated its ability to handle massive traffic surges during Black Friday and Cyber Monday 2025, processing over 115.8 billion requests with consistent performance. Key metrics include 518,027 peak requests per second, 6.1 million deployments, 24 million AI Gateway requests, 43.2 billion Fluid compute invocations, 56.9 billion cache hits, 1.8 billion ISR reads, 1.5 billion ISR writes, 7.5 billion firewall actions, 415 million bots blocked, and 2.4 billion humans verified. This post details Vercel's response to a critical npm supply chain attack, including identifying affected projects, purging build caches, and notifying customers. The attack involved compromised npm packages (`chalk`, `debug`, `ansi-styles`) containing wallet-drainer malware. Vercel's security and engineering teams acted rapidly to mitigate the impact by identifying and purging build caches for all affected projects, ensuring that Vercel customers were not impacted by the malicious code. The incident response timeline and technical details of the phishing campaign targeting npm maintainers are also provided, along with recommendations for customers to enhance their dependency management and security practices. Vercel also outlines ongoing prevention measures to strengthen its supply chain security posture.

2025

Critical npm supply chain attack response – September 8, 2025

9/8/2025

This post details Vercel's response to a critical npm supply chain attack, including identifying affected projects, purging build caches, and notifying customers. The attack involved compromised npm packages (`chalk`, `debug`, `ansi-styles`) containing wallet-drainer malware. Vercel's security and engineering teams acted rapidly to mitigate the impact by identifying and purging build caches for all affected projects, ensuring that Vercel customers were not impacted by the malicious code. The incident response timeline and technical details of the phishing campaign targeting npm maintainers are also provided, along with recommendations for customers to enhance their dependency management and security practices. Vercel also outlines ongoing prevention measures to strengthen its supply chain security posture.