top of page
perceptive_background_267k.jpg

binding.gyp: An npm Supply Chain Attack That Spreads Like a Worm

Published:

4 juni 2026 om 03:47:39

Alert date:

4 juni 2026 om 04:00:30

Source:

stepsecurity.io

Click to open the original link from this advisory

Supply Chain & Dependencies

A self-replicating worm is spreading across the npm registry using binding.gyp files to execute malicious code during npm install operations. The attack bypasses conventional security tools by avoiding package.json scripts and instead leverages binding.gyp files which trigger automatic code execution. The worm has successfully compromised dozens of npm packages across multiple maintainer accounts. This supply chain attack spreads autonomously like a worm, making it particularly dangerous for the JavaScript ecosystem. The attack demonstrates a novel technique that security tools are not currently detecting effectively.

Technical details

Mitigation steps:

Affected products:

npm
Node.js

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page