npm Hijacking Wave: coa, rc, node-ipc and Stolen Maintainers
Popular packages with dormant maintainers pushed info-stealers through postinstall scripts. The registry was fine; the accounts were not.
Popular packages with dormant maintainers pushed info-stealers through postinstall scripts. The registry was fine; the accounts were not.
The SolarWinds actor returned with no implant at all — sprayed passwords, replayed tokens, and delegated partner admin rights over 609 channel companies.
One maintenance command withdrew Facebook’s backbone routes, took DNS with it, and locked engineers out of the fix. The outage defended itself.
A single encoded GET walked out of Apache’s docroot, and the first patch didn’t hold. Inside the October 2021 traversal zero-day scramble.
October 2021’s FSB operation ended REvil with arrests, asset seizures, and infrastructure capture. The talent lived on elsewhere.
No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.
A forged keeper-list substitution drained $611M across three chains. Then the attacker gave it all back. The bridge bug class that defined Web3’s worst year.
Three patched-but-unapplied Exchange bugs chained into unauthenticated RCE. Webshells, mailbox theft, and ransomware followed at population scale within two weeks.
PetitPotam coerced Windows machines to authenticate, AD CS web enrollment happily minted a DC certificate, and domains fell in an afternoon. The relay class is still with us.
One broken inheritance flag left Windows SAM, SYSTEM, and SECURITY hives readable by any user. With shadow copies in play, that meant every local NTLM hash on the box.
The Pegasus Project exposed 50,000 targeted numbers and a hard truth: modern mercenary spyware infects phones through iMessage and WhatsApp without the victim doing anything.