Executive brief
The backslash npm package, a JavaScript utility for parsing escaped strings, was compromised after its publisher's npm account was taken over via phishing. Version 0.2.1 contains malware that intercepts cryptocurrency transactions in browser environments and redirects them to attacker-controlled addresses. This affects any application that bundles the package for browser use, such as web applications using build tools like Webpack, Vite, or Next.js.
Technical details
This is a supply-chain attack involving malicious code injection (CWE-506) following account compromise via phishing. The attacker gained control of the npm publishing account on September 8, 2025, and published version 0.2.1 with obfuscated malware appended to the legitimate package code. The malware intercepts cryptocurrency transaction objects and replaces recipient addresses with one of 26 attacker-controlled Ethereum addresses. The payload only executes in browser contexts (checks `typeof window !== 'undefined'`) and does not affect Node.js server or CLI environments. Attack vector is network-based: compromise occurs when users install the affected version from npm registry or private mirrors. The malware specifically targets cryptocurrency wallets such as MetaMask. npm removed the package from its public registry on September 8; patched versions (0.2.2+) were published September 13. Users must upgrade, delete node_modules, clear package manager caches, and rebuild browser bundles to remove the malware.
Affected products
- npm backslash 0.2.1
Timeline
- 2025-09-08: other: npm publishing account for backslash compromised via phishing; version 0.2.1 with malware payload published
- 2025-09-15: disclosed: Security advisory GHSA-53mq-f4w3-f7qv published; CVE-2025-59140 assigned
- 2025-09-13: patched: Patched version 0.2.2 published to help cache-bust
References
- https://github.com/Qix-/node-backslash/security/advisories/GHSA-53mq-f4w3-f7qv
- https://github.com/debug-js/debug/issues/1005
- https://github.com/Qix-/node-backslash
- https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack
- https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
- https://www.ox.security/blog/npm-packages-compromised