NPM package ‘is’ with 2.8M weekly downloads infected devs with malware

https://www.bleepingcomputer.com/news/security/npm-package-is-with-28m-weekly-downloads-infected-devs-with-malware/

56 points · 3 comments · view on lemmy.world

3 Comments

HubertManne@piefed.social · 10 pts · 1y

holy crap:

On July 19, 2025, the package's primary maintainer, John Harband, announced that versions 3.3.1 through 5.0.0 contained malware and were removed roughly 6 hours after threat actors submitted them to npm.

Cyber@feddit.uk · 4 pts · 1y (1 reply)

So, is that just a 'developer' component, or have I got to analyse all my systems now for the NPM components in the article's list?

freewheel@sh.itjust.works · 2 pts · 1y

Little late to the party here, and I'm not primarily a js dev, but... yes. It looks like it's one of those syntactic sugar kind of packages that devs love to use. The bonus here is you can probably use a find-grep kind of process to check package-lock.json for references to the package. (there might be an npm command, but like I say - not a js dev.)

For example:

$ grep \"is\"\: package-lock.json
        "is": "^3.3.0",