{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/npm-all-versions/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["npm (all versions)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eMalicious npm packages and supply-chain compromises frequently abuse Node.js lifecycle scripts (such as \u003ccode\u003einstall\u003c/code\u003e or \u003ccode\u003epostinstall\u003c/code\u003e) to fetch second-stage payloads from remote infrastructure. Attackers leverage the trust inherent in package management workflows to execute code during the \u003ccode\u003enpm install\u003c/code\u003e or \u003ccode\u003enpx\u003c/code\u003e process. This threat specifically involves the spawning of \u003ccode\u003ecurl\u003c/code\u003e from within a Node.js process tree initiated by \u003ccode\u003enpm\u003c/code\u003e or \u003ccode\u003enpx\u003c/code\u003e CLI tools. By using short command-line arguments and standard output redirection or shell execution, these malicious scripts attempt to minimize their footprint while retrieving external malicious resources. Defenders should monitor for Node.js-originated processes that invoke curl to download remote files, as this is a high-fidelity indicator of potential dependency tampering.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to gain arbitrary code execution within the build environment or developer workstation. This can lead to the exfiltration of sensitive environment variables, developer credentials, and project-specific API tokens, or result in the injection of persistent backdoors into build artifacts, potentially affecting downstream users of the compromised software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for child processes spawned by Node.js package managers to identify unauthorized outbound network connectivity.\u003c/li\u003e\n\u003cli\u003eReview \u003ccode\u003epackage.json\u003c/code\u003e lifecycle scripts for suspicious activity or obfuscated commands before executing dependency installations in CI/CD pipelines.\u003c/li\u003e\n\u003cli\u003eIsolate build environments and restrict internet access for package manager processes, allowing only access to trusted, hardened private registries.\u003c/li\u003e\n\u003cli\u003eInvestigate any \u003ccode\u003ecurl\u003c/code\u003e activity initiated by npm or npx process trees identified in endpoint telemetry.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T10:10:34Z","date_published":"2026-09-28T10:10:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-npm-curl-supply-chain/","summary":"Malicious npm packages and supply-chain compromises often utilize installation scripts to spawn curl processes that download secondary payloads from remote servers.","title":"Detection of Malicious Curl Downloads during npm Package Installation","url":"https://feed.craftedsignal.io/briefs/2026-09-npm-curl-supply-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Npm (All Versions)","version":"https://jsonfeed.org/version/1.1"}