npm Supply Chain Attack Hits Packages With Billions of Weekly Downloads – Advisory By SISA Sappers

A phishing-led npm supply chain attack briefly compromised 18 popular packages (~2.6B weekly downloads), injecting code to hijack crypto wallet transactions. Malicious versions were live for ~2.5 hours on Sept 8, 2025, before removal. Learn the impact, affected packages, IoCs, and steps to secure builds, dependencies, and developer accounts.

Point of View: Salesforce OAuth Breach — A Paradigm Shift in SaaS Security

The Salesforce OAuth breach by UNC6395, impacting 700+ enterprises, reveals a critical shift in cyber risk to SaaS supply chains. SISA’s analysis underscores the urgent need for robust OAuth governance, cross-platform monitoring, and board-level integration security to prevent future ecosystem-wide compromises.

SISA’s Latest
close slider