


Perceptive Security
SOC/SIEM Consultancy

binding.gyp: An npm Supply Chain Attack That Spreads Like a Worm
Published:
4 juni 2026 om 03:47:39
Alert date:
4 juni 2026 om 04:00:30
Source:
stepsecurity.io
Supply Chain & Dependencies
A self-replicating worm is spreading across the npm registry using binding.gyp files to execute malicious code during npm install operations. The attack bypasses conventional security tools by avoiding package.json scripts and instead leverages binding.gyp files which trigger automatic code execution. The worm has successfully compromised dozens of npm packages across multiple maintainer accounts. This supply chain attack spreads autonomously like a worm, making it particularly dangerous for the JavaScript ecosystem. The attack demonstrates a novel technique that security tools are not currently detecting effectively.
Technical details
Mitigation steps:
Affected products:
npm
Node.js
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
