Skip to content
Rise of Malicious npm Packages Threatens Developer Trust

Rise of Malicious npm Packages Threatens Developer Trust

First seen 27 Sep 2026, 19:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 19:57 UTC
  • •1.8 million malicious packages logged, with npm comprising 96.6% of the total.
  • •ReversingLabs identified a malicious npm package targeting Twilio developers to exfiltrate data.
  • •npm plans to implement pre-publish scanning to combat the rising threat of malicious packages.

As of Q2 2026, Sonatype Research logged 1.8 million malicious packages, with npm accounting for 96.6% of this total. The quarter saw a surge in repository abuse, trojan-class malware, and maintainer compromises, indicating a shift towards targeting trusted developer workflows. ReversingLabs reported a specific malicious npm campaign that compromised packages related to Twilio, aiming to exfiltrate sensitive data. The number of malicious npm packages has risen sharply, with 5723 unique packages identified by August 2026, surpassing the total for all of 2024. Despite npm's efforts to implement pre-publish scanning to mitigate these threats, the volume of malicious packages continues to grow. Attackers are employing social engineering tactics and exploiting trusted packages, with notable campaigns like Shai-Hulud leading to widespread infections. The overall threat landscape remains concerning, with a significant concentration of malicious activity across various ecosystems, particularly npm, PyPI, and NuGet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-01
Shai-Hulud campaign variants emerge
Multiple variants of the Shai-Hulud malware campaign appear, compromising trusted packages and increasing supply chain risks.
ReversingLabs
2026-08-01
Malicious npm packages exceed 5723
ReversingLabs reports that the number of unique malicious npm packages reached 5723 by August 2026, surpassing the total for all of 2024.
ReversingLabs
2026-09-24
Sonatype reports 1.8 million malicious packages
Sonatype Research reveals that npm accounts for 96.6% of logged malicious packages, highlighting a significant rise in repository abuse.
Sonatype

More articles in this cluster (2)

Following this threat?

Track Shai-hulud and Twilio in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed