Four npm Supply Chain Attacks in Six Weeks

▶ Watch (1:57)

In late August and early September 2026, attackers injected a credential-harvesting script into a GitHub Actions workflow (Singularity), leaking thousands of secrets. A week and a half later, a spear-phished npm maintainer pushed a crypto stealer downloaded 2.5 million times. Two self-replicating worms followed: Shy Halude exfiltrated secrets and exposed private repos, and a second worm backdoored nearly 800 npm packages, affecting over 500 GitHub users.

Incident Response: Assign Responsibilities and Train Early

▶ Watch (4:57)

Toomey stresses the bystander effect: during an emergency, people assume someone else will act. In security incidents, leaders must point directly to individuals and say, “You, do this.” Teams need pre-agreed roles. Developers and DevOps engineers should train on expected actions before an attack. Communicate with leadership that incident response becomes top priority and normal work stops.

Proactive Defenses: Fine-Grained Tokens and Minimum Package Age

▶ Watch (9:18)

Datadog detected malicious PRs against an open source repo and prevented merges with org-wide configurations. Proactive defenses include fine-grained access tokens instead of personal access tokens, and mandatory MFA. A newer defense is minimum package age: tools like yarn, pnpm, and Dependabot’s cool down wait days before auto-upgrading, giving researchers time to spot malicious packages.

Post-Incident Retrospective and Documentation

▶ Watch (11:53)

After urgency drops, run a retrospective: what went well and what didn’t. Investigate if you could find malicious versions easily, if teams faced friction, if a communications plan existed. Fix gaps. Document everything: write steps, affected systems, outcomes. Create templates for leadership and customer emails. Write standard operating procedures so the next incident can be investigated faster.

Team Care: Check-Ins, Mandatory Fun, and Food

▶ Watch (14:57)

Incidents take weeks and are exhausting. Toomey urges checking in on teammates: skip meals, miss family events. After an incident, take personal time. Leadership should schedule mandatory fun not the next day, but later: a game, team lunch, comp time off. 99% of people appreciate being appreciated. Free food delivery during incidents also boosts morale.

Q&A

Has minimum package age seen supply chain attacks adapt with time-based malware? Toomey says no, because the feature is new and not widely used yet, only in yarn and pnpm, not npm. ▶ Watch (23:15)

What’s the fastest response time for a supply chain incident? She says minutes with a global team or paging system; depends on team distribution. ▶ Watch (24:19)

Notable Quotes

another one bites the dust. Get it? Kennedy Toomey · ▶ Watch (1:33)

maybe these dependencies are a chain of fools Kennedy Toomey · ▶ Watch (3:38)

Why do you write like you’re running out of time Kennedy Toomey · ▶ Watch (13:12)

check in on your team. These events, they’re stressful. They’re high pressure. They’re exhausting. Kennedy Toomey · ▶ Watch (15:11)

0% of people will turn down free food delivery during these events Kennedy Toomey · ▶ Watch (17:54)

Key Takeaways

  • Assign specific responsibilities during incidents to avoid the bystander effect.
  • Use minimum package age in yarn/pnpm to delay auto-upgrades and catch malicious packages.
  • After an incident, run a retro, document findings, and create SOPs for faster future response.

About the Speaker(s)

Kennedy Toomey is an Application Security Researcher & Advocate at Datadog. Previously she was an Application Security Engineer where she spent her time working with developers to help fix vulnerabilities and write more secure code.