Published: September 8, 2025
33
115
786

Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.

@_SEAL_Org Did we get lucky or is everybody prepared for such cases by now?

@rimeissner Definitely got lucky - this could've been much worse. A stealthily deployed backdoor that targeted developer machines with a focus on persistence could have stayed under the radar for who knows how long

@_SEAL_Org @grok explain this

@_SEAL_Org @not_nothingmuch It wasn't done for money. Any guesses which state-affiliated hacker group pulled it off?

@_SEAL_Org is $50 enough to retire?

@_SEAL_Org Peak bear market energy is risking prison for less than a gas fee

@_SEAL_Org What is the weak point in this way of developing and how can this be prevented from now on?

@_SEAL_Org seems like2am thoughts hit harder when reality checks cost just

@_SEAL_Org Can you please shed some light on this question? https://x.com/EthosVentures/st...

@_SEAL_Org Billions in potential, pennies in execution

@_SEAL_Org I guess that went quick... but are we yet safe tho?

@_SEAL_Org stay safe

@_SEAL_Org Vibe hackers

@_SEAL_Org 👀

@_SEAL_Org @inversebrah sophisticated DPRK agents at work

@_SEAL_Org Wen gofundme for the hacker?

@_SEAL_Org Feels like we are going to witness this more often.

@_SEAL_Org Shows both resilience and fragility

@_SEAL_Org Maybe he just wanted to scare us and not inflict any damage.

@_SEAL_Org Amazing

Image in tweet by Security Alliance

@_SEAL_Org What about the big accounts that claimed to have lost millions recently? Did they orchestrate this to avoid paying taxes?

@_SEAL_Org This is generational wealth in some places in the world.

@_SEAL_Org Is the coast clear to make these jokes?

@_SEAL_Org No branch protection rules? Really looking forward to someone with a deep dive on this hack😂 @lewiswambugu01/detecting-npm-malicious-packages-in-your-local-repositories-app-with-ripgrep-what-to-do-upon-804f12791972 class="text-blue-500 hover:underline" target="_blank" rel="noopener noreferrer">https://medium.com/@lewiswambu...

@_SEAL_Org or they just feel sorry

@_SEAL_Org Unlimited access squandered for pennies

@_SEAL_Org 💀💀💀

@_SEAL_Org Seems like the risk didn't quite pay off as expected

Share this thread

Read on Twitter

View original thread

Navigate thread

1/31