# The BIGGEST Software Supply Chain Attack in History - Threat Wire

Source: https://www.youtube.com/watch?v=369FyDCjecg
Recap page: https://rapidrecap.app/video/369FyDCjecg
Generated: 2025-09-10T17:31:38.019+00:00

---
## Quick Overview

The biggest software supply chain attack in history occurred when the NPM debug and chalk packages were compromised, leading to the distribution of malicious code and affecting an average of over 2 billion downloads per week within the JavaScript ecosystem.

**Key Points:**
- The largest software supply chain attack occurred on Monday, September 8th, 2025, affecting the NPM package manager.
- Eighteen popular NPM packages, including 'debug' and 'chalk', were compromised with malicious code.
- The attack was discovered by the team at Akidoi, who alerted NPM to the compromised packages.
- The malicious code was designed to intercept API calls and rewrite cryptocurrency transactions.
- The attacker, Josh Junon (GitHub user 'Right9Ctrl'), gained access through a phishing attack targeting a two-factor authentication reset email.
- Junon admitted to the attack in a public post, stating he should have paid more attention and intended to clean it up.
- The compromised packages were removed from NPM, and updates were pushed to remove the malicious code.

![Screenshot at 00:12: The title card clearly states "The Largest Supply Chain Attack", indicating the video's central theme.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-00-12.png)

**Context:** On September 8th, 2025, a significant security incident rocked the JavaScript ecosystem when the widely used NPM (Node Package Manager) was targeted in what is considered the largest software supply chain attack to date. The attack involved the compromise of popular packages like 'debug' and 'chalk', which were then used to distribute malicious code to millions of developers worldwide.

## Detailed Analysis

On September 8th, 2025, the NPM package manager experienced the largest software supply chain attack in history. Eighteen popular packages, including 'debug' and 'chalk', were compromised with malicious code. This code was designed to intercept API calls and rewrite cryptocurrency transactions, potentially draining users' wallets. The attack was discovered by Akidoi security researchers who quickly alerted NPM. The perpetrator, identified as Josh Junon (GitHub user 'Right9Ctrl'), admitted to the attack via a public post, attributing it to a successful phishing attempt that targeted his two-factor authentication reset email. Junon expressed regret and stated his intention to rectify the situation. Following the discovery, the compromised packages were removed from NPM, and updates were released to clean the malicious code from affected systems. The incident highlights the vulnerabilities inherent in open-source software development and the potential impact of compromised dependencies.

### Attack Details

- On September 8th, 2025, 18 NPM packages including 'debug' and 'chalk' were compromised
- malicious code was injected, designed to intercept API calls and rewrite cryptocurrency transactions
- attacker gained access via a phishing attack on a 2FA reset email

### Discovery and Response

- Akidoi security researchers discovered the attack and alerted NPM
- compromised packages were removed and malicious code was purged via updates

### Attacker's Admission

- Attacker, Josh Junon (GitHub user 'Right9Ctrl'), admitted to the attack and apologized
- cited personal stress as a contributing factor

### Broader Implications

- Highlights the significant risks in software supply chains
- emphasizes the need for robust security practices in open-source development

![Screenshot at 00:12: Title card displaying "The Largest Supply Chain Attack".](https://ss.rapidrecap.app/screens/369FyDCjecg/00-00-12.png)
![Screenshot at 00:17: The host introduces the topic of the NPM package compromise.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-00-17.png)
![Screenshot at 00:20: A list of the compromised NPM packages is displayed, showing 'debug', 'chalk', and others.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-00-20.png)
![Screenshot at 00:42: The host describes the nature of the attack, involving malicious code.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-00-42.png)
![Screenshot at 00:57: A tweet from Josh Junon admitting to the compromise and explaining the phishing incident.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-00-57.png)
![Screenshot at 01:15: Junon's tweet detailing the phishing attack and his regret.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-01-15.png)
![Screenshot at 01:42: An article title from Apiiro blog: "4x Velocity, 10x Vulnerabilities: AI Coding Assistants Are Shipping More Risks".](https://ss.rapidrecap.app/screens/369FyDCjecg/00-01-42.png)
![Screenshot at 02:02: The title "AI Can't Code Security" appears, suggesting a discussion on AI's role in security.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-02-02.png)
![Screenshot at 02:48: A new title appears: "Malicious TLS Certificates Discovered".](https://ss.rapidrecap.app/screens/369FyDCjecg/00-02-48.png)
![Screenshot at 03:02: A report titled "Incident Report: Mis-issued Certificates for SAN IPAddress:1.1.1.1 by Fina RDC 2020" is displayed.](https://ss.rapidrecap.app/screens/369FyDCjecg/00-03-02.png)
