FixVibe

critical

Node-gyp Supply Chain Compromise: Self-Propagating npm Worm in binding.gyp

Security researchers have identified a supply chain compromise involving a self-propagating npm worm. The malicious payload is designed to hide within binding.gyp files, which are typically used by node-gyp for compiling native addon modules.

CWE-506CWE-494

Attacker Impact

A malicious npm package version in this campaign can execute during dependency installation through the node-gyp build path. Public research reported credential harvesting and self-propagation behavior across dozens of packages, so affected installs should be treated as supply-chain compromise evidence rather than a normal dependency vulnerability.

Root Cause

The campaign relied on package metadata and build-file behavior that can run during installation even when the package does not declare a normal lifecycle script. That makes repository manifests, lockfiles, and committed build files useful places to look for exposure without running the package.

Concrete Fixes

  • Remove or replace any affected package version and regenerate the active npm, pnpm, or Yarn lockfile from trusted registry state.
  • Remove any unexpected node-gyp build-file execution artifact from owned source after reviewing adjacent loader files as text only.
  • Clear dependency caches, rebuild CI images, devcontainers, Docker layers, and deployment artifacts that may have installed the package.
  • Rotate npm, GitHub, cloud, SSH, deployment, and CI credentials that were available to environments where the package may have installed.
  • Verify through dependency-tree, lockfile, source review, and clean build artifacts. Do not execute affected packages or build scripts for proof.

Covered by FixVibe

FixVibe's GitHub repo scans flag repositories whose manifests or lockfiles resolve known malicious npm package versions from this campaign, or whose source contains the node-gyp build-file execution pattern described in public campaign research [S1], [S2], [S3]. If a finding appears, remove the affected dependency or source artifact, rebuild install caches and CI images, and rotate credentials that may have been available during installation.

Node-gyp Supply Chain Compromise: Self-Propagating npm Worm in binding.gyp