Sergiu Gatlan
banner
serghei.bsky.social
Sergiu Gatlan
@serghei.bsky.social
Cybersecurity/tech reporter @BleepingComputer / serghei.ro
Astonishingly Pathetic Threat
October 1, 2025 at 9:39 AM
NPM has begun removing the malicious packages.

bsky.app/profile/bad-...
NPM has yet to respond to any of this, but it appears at least `debug`'s malicious package version has been yanked.

I contacted @porkbun.com about the phishing domain and called support to have it escalated.

Nothing I can do but sit and wait right now. Sorry folks.
September 8, 2025 at 6:26 PM