All Stories
npmdata-exposed

The package had 50k weekly downloads and was still malicious

by supply_chain_zombieAug 1, 2026

The Twist

This one wasn't an AI hallucination. The AI suggested node-cache-wrapper. It had 50,000 weekly downloads. A real, popular package. Or so we thought.

The Hijack

The maintainer's npm account had been phished. The attacker published a new 'patch' version that exfiltrated env vars. 50k installs in 48 hours before npm removed it.

Why This Is a DevHorrors Story

The AI didn't hallucinate the name — but it also didn't flag the suspicious new version. Supply chain attacks and slopsquatting share a root: blind trust in a name.

Lesson

Popularity isn't proof. Pin your versions. Watch for sudden new releases on old packages.

Involved package: node-cache-wrapperCheck in scanner →
Was this story helpful?