# npm Supply Chain Attack via Open Source maintainer compromise

DevFeed: [npm Supply Chain Attack via Open Source maintainer compromise](<https://devfeed.tech/articles/npm-supply-chain-attack-via-open-source-maintainer-compromise-8036.md>)

Original publisher: [Read original article](<https://snyk.io/blog/npm-supply-chain-attack-via-open-source-maintainer-compromise/>)

Author: Brian Clark

Published: 2025-09-08T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [browser](<https://devfeed.tech/tags/browser.md>), [developer](<https://devfeed.tech/tags/developer.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

## AI overview

A phishing compromise of an npm maintainer allowed an attacker to publish malicious package versions. The injected browser-side code targeted Web3 wallets by intercepting and modifying cryptocurrency transactions.

## Source excerpt

On Monday, September 8th, a highly regarded open source developer, ~qix, was compromised via a phishing email.