All Stories
npmdata-exposed
The package had 50k weekly downloads and was still malicious
by supply_chain_zombieAug 1, 2026
The Twist
This one wasn't an AI hallucination. The AI suggested node-cache-wrapper. It had 50,000 weekly downloads. A real, popular package. Or so we thought.
The Hijack
The maintainer's npm account had been phished. The attacker published a new 'patch' version that exfiltrated env vars. 50k installs in 48 hours before npm removed it.
Why This Is a DevHorrors Story
The AI didn't hallucinate the name — but it also didn't flag the suspicious new version. Supply chain attacks and slopsquatting share a root: blind trust in a name.
Lesson
Popularity isn't proof. Pin your versions. Watch for sudden new releases on old packages.
Involved package: node-cache-wrapperCheck in scanner →
Was this story helpful?