Four npm Supply Chain Attacks in Six Weeks
In late August and early September 2026, attackers injected a credential-harvesting script into a GitHub Actions workflow (Singularity), leaking thousands of secrets. A week and a half later, a spear-phished npm maintainer pushed a crypto stealer downloaded 2.5 million times. Two self-replicating worms followed: Shy Halude exfiltrated secrets and exposed private repos, and a second worm backdoored nearly 800 npm packages, affecting over 500 GitHub users.
Incident Response: Assign Responsibilities and Train Early
Toomey stresses the bystander effect: during an emergency, people assume someone else will act. In security incidents, leaders must point directly to individuals and say, “You, do this.” Teams need pre-agreed roles. Developers and DevOps engineers should train on expected actions before an attack. Communicate with leadership that incident response becomes top priority and normal work stops.
Proactive Defenses: Fine-Grained Tokens and Minimum Package Age
Datadog detected malicious PRs against an open source repo and prevented merges with org-wide configurations. Proactive defenses include fine-grained access tokens instead of personal access tokens, and mandatory MFA. A newer defense is minimum package age: tools like yarn, pnpm, and Dependabot’s cool down wait days before auto-upgrading, giving researchers time to spot malicious packages.
Post-Incident Retrospective and Documentation
After urgency drops, run a retrospective: what went well and what didn’t. Investigate if you could find malicious versions easily, if teams faced friction, if a communications plan existed. Fix gaps. Document everything: write steps, affected systems, outcomes. Create templates for leadership and customer emails. Write standard operating procedures so the next incident can be investigated faster.
Team Care: Check-Ins, Mandatory Fun, and Food
Incidents take weeks and are exhausting. Toomey urges checking in on teammates: skip meals, miss family events. After an incident, take personal time. Leadership should schedule mandatory fun not the next day, but later: a game, team lunch, comp time off. 99% of people appreciate being appreciated. Free food delivery during incidents also boosts morale.
Q&A
Has minimum package age seen supply chain attacks adapt with time-based malware? Toomey says no, because the feature is new and not widely used yet, only in yarn and pnpm, not npm. ▶ Watch (23:15)
What’s the fastest response time for a supply chain incident? She says minutes with a global team or paging system; depends on team distribution. ▶ Watch (24:19)
Notable Quotes
another one bites the dust. Get it? Kennedy Toomey · ▶ Watch (1:33)
maybe these dependencies are a chain of fools Kennedy Toomey · ▶ Watch (3:38)
Why do you write like you’re running out of time Kennedy Toomey · ▶ Watch (13:12)
check in on your team. These events, they’re stressful. They’re high pressure. They’re exhausting. Kennedy Toomey · ▶ Watch (15:11)
0% of people will turn down free food delivery during these events Kennedy Toomey · ▶ Watch (17:54)
Key Takeaways
- Assign specific responsibilities during incidents to avoid the bystander effect.
- Use minimum package age in yarn/pnpm to delay auto-upgrades and catch malicious packages.
- After an incident, run a retro, document findings, and create SOPs for faster future response.
About the Speaker(s)
Kennedy Toomey is an Application Security Researcher & Advocate at Datadog. Previously she was an Application Security Engineer where she spent her time working with developers to help fix vulnerabilities and write more secure code.