By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Hacker Pwns Programmer, Infects Widely Used Software With Malware
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Hacker Pwns Programmer, Infects Widely Used Software With Malware
News

Hacker Pwns Programmer, Infects Widely Used Software With Malware

News Room
Last updated: 2025/09/08 at 7:57 PM
News Room Published 8 September 2025
Share
SHARE

Don’t miss out on our latest stories. Add PCMag as a preferred source on Google.


A hacker has managed to infect over a dozen widely used software packages with a crypto-looting malware after successfully phishing the programmer responsible for maintaining them. 

This morning, the malware was found in 18 software modules that together have been downloaded 2 billion times per week, according to Aikido Security. The problem affects a group of popular “npm packages” that provide essential functionality for JavaScript projects, such as converting fonts and adding colors to text.

The programmer responsible for maintaining the npm packages, Josh Junon, posted on Monday, “Yep, I’ve been pwned,” attributing the hack to a phishing email, which was apparently sent to multiple users. The phishing email pretended to come from the official npmjs.com domain, which GitHub owns, by using the official logos. But in this case, the phishing email originated from a fake domain at npmjs[.]help.

(Credit: Aikido Security)

The attack also worked by posing as a security-related alert, urging the recipient to update their two-factor authentication. The phishing email included a link that appears to have led to a hacker-controlled domain, which then stole access to Junon’s account to maintain the npm packages. 

The breach prompted Aikido Security to describe it as “the largest supply chain compromise in npm history.” However, the computer programming community was quick to flag the issue after the affected npm packages were found to contain malicious processes. Some of the affected npm packages have already been removed.

“As these versions were only available for a short period of time and (based on data from npm) did not have any downloads, the impact of this malware is likely minimal,” according to security app provider Semgrep. 

Recommended by Our Editors


This Tweet is currently unavailable. It might be loading or has been removed.

Meanwhile, BleepingComputer reports that a software project would have needed to fulfill three criteria in order to have been affected with malware, limiting the attack’s impact.

“The compromise was significant. But the payload was amateur-grade. My honest opinion: all they had was access – not skill,” added security researcher Florian Roth. Still, there are some signs the hacker may have successfully targeted other npm package maintainers.

The hacker’s malware focuses on stealing cryptocurrency by hijacking and manipulating the user’s browser. “Simply put, the actor swaps any crypto transactions to their own address, redirecting any currency to their accounts,” another app security provider named Socket said.


Newsletter Icon

Newsletter Icon

Get Our Best Stories!

Stay Safe With the Latest Security News and Updates


SecurityWatch Newsletter Image

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.

Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

About Michael Kan

Senior Reporter

Michael Kan

I’ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I’m currently based in San Francisco, but previously spent over five years in China, covering the country’s technology sector.

Read Michael’s full bio

Read the latest from Michael Kan

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article With the SEC on the Sidelines, Nasdaq Becomes Crypto’s New Sheriff | HackerNoon
Next Article How I Made $33,429.84 in August as a Content Creator
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The Ultimate Guide to Creating Scroll-Stopping Social Media Hooks
Computing
Apple Event 2025: The 8 product announcements we expect today, including iPhone 17
News
Why small businesses and shoppers should care about ‘de minimis’ tariffs
News
WIN a £100 CEWE photobook voucher to preserve your digital memories | Stuff
Gadget

You Might also Like

News

Apple Event 2025: The 8 product announcements we expect today, including iPhone 17

8 Min Read
News

Why small businesses and shoppers should care about ‘de minimis’ tariffs

3 Min Read
News

You Can Create A Custom Alarm Sound On Your iPhone – Here’s How – BGR

5 Min Read
News

Google pulls the Pixel 10’s Daily Hub to ‘enhance its performance’

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?