Backdoored npm Packages Used Bun Runtime to Steal Secrets and Self-Propagate
On November 24, 2025, security researchers identified hundreds of backdoored npm packages that silently downloaded the Bun JavaScript runtime during installation to evade standard Node.js monitoring tools. The malicious packages, found under well-known scopes including Zapier, Postman, and PostHog, used a preinstall hook to fetch Bun and execute a heavily obfuscated payload in the background. The payload deployed TruffleHog to scan for credentials, queried cloud metadata services on AWS, Azure, and Google Cloud, and exfiltrated stolen data to GitHub repositories created in victims' own accounts. Using stolen npm tokens, the worm then injected itself into up to 100 of each compromised maintainer's packages and republished them, effectively spreading itself further. Datadog reported over 796 backdoored packages affecting more than 500 GitHub users and 150 organisations, while Socket placed the count at over 500 packages, with the last known malicious publish recorded at 6 p.m. UTC on November 24.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in