npm Supply Chain Security
Critical npm supply chain attack response – September 8, 2025

Critical npm supply chain attack response – September 8, 2025

9/8/2025

What this post added

This post details Vercel's response to a critical npm supply chain attack, including identifying affected projects, purging build caches, and notifying customers. The attack involved compromised npm packages (`chalk`, `debug`, `ansi-styles`) containing wallet-drainer malware. Vercel's security and engineering teams acted rapidly to mitigate the impact by identifying and purging build caches for all affected projects, ensuring that Vercel customers were not impacted by the malicious code. The incident response timeline and technical details of the phishing campaign targeting npm maintainers are also provided, along with recommendations for customers to enhance their dependency management and security practices. Vercel also outlines ongoing prevention measures to strengthen its supply chain security posture.

Read the original post ↗