Post

Log inSign up

Post

Log inSign up

npm on X: "following ongoing investigations, we identified in real time multiple versions of the “rc” package containing identical malware to the “coa” package. malicious versions of “rc” were immediately removed from the registry and we have published an advisory: https://t.co/9MoSyhAt3S"

@npmjs
npm
GitHub
@npmjs
following ongoing investigations, we identified in real time multiple versions of the “rc” package containing identical malware to the “coa” package. malicious versions of “rc” were immediately removed from the registry and we have published an advisory:
github.com
GHSA-g2q5-5433-rhrf - GitHub Advisory Database
Embedded malware in rc
11:10 PM · Nov 4, 2021·
4

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email

Relevant people

Avatar
npm@npmjsFollow
The package manager for JavaScript Problems? Visit https://t.co/WNuo1MMbMP or https://t.co/i3MoAdr5p5

Trending now

Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.
  • @npmjs
    npm
    GitHub
    @npmjs
    Nov 4, 2021
    this morning we detected multiple versions of the “coa” package published with malicious code due to a compromised account of a maintainer. we quickly removed the compromised versions and have published an advisory: github.com/advisories/GHS…. npm itself was not compromised. [1/3]
    github.com
    GHSA-73qr-pfmq-6rp8 - GitHub Advisory Database
    Embedded malware in coa
    7
  • @npmjs
    npm
    GitHub
    @npmjs
    Nov 4, 2021
    the compromised account has been temporarily disabled and we are actively investigating the incident and monitoring for similar activity. we will share additional information as appropriate based on our investigation. [2/3]
    2
  • @npmjs
    npm
    GitHub
    @npmjs
    Nov 4, 2021
    to protect your accounts and packages from similar attacks, we highly recommend enabling 2FA on your npm account: docs.npmjs.com/configuring-tw…. [3/3]
    Configuring two-factor authentication | npm Docs
    From docs.npmjs.com
    10
  • @npmjs
    npm
    GitHub
    @npmjs
    following ongoing investigations, we identified in real time multiple versions of the “rc” package containing identical malware to the “coa” package. malicious versions of “rc” were immediately removed from the registry and we have published an advisory:
    github.com
    GHSA-g2q5-5433-rhrf - GitHub Advisory Database
    Embedded malware in rc
    11:10 PM · Nov 4, 2021·
    4
  • @Kelset
    Lorenzo 'kelset' Sciandra
    @Kelset
    Nov 5, 2021
    folks you should at least give us a timeline of: * when they were published * how long they were available for without those data, how can we asses damage?
  • @b0neskull
    boneskull mcboneskullface
    @b0neskull
    Nov 4, 2021
    sooo how did this happen?
    1
  • @spidero_7
    Bartłomiej Pająk
    @spidero_7
    Nov 5, 2021
    How about 8.1.0 version comes with node.js? Uninstall or what?