{"id":281175,"date":"2025-06-08T09:35:07","date_gmt":"2025-06-08T09:35:07","guid":{"rendered":"https:\/\/peraltafinancing.com\/uncategorized\/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads\/"},"modified":"2025-06-08T09:35:07","modified_gmt":"2025-06-08T09:35:07","slug":"supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=281175","title":{"rendered":"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" alt=\"NPM\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2025\/05\/08\/npm.jpg\" width=\"1600\"\/><\/p>\n<p>A significant supply chain attack hit NPM after 16\u00a0popular Gluestack &#8216;react-native-aria&#8217; packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT).<\/p>\n<p>BleepingComputer determined that the compromise began on June 6 at 4:33 PM EST, when a new version of the\u00a0react-native-aria\/focus package was published to NPM.\u00a0Since then, 16 of the 20 Gluestack <a href=\"https:\/\/www.npmjs.com\/org\/react-native-aria\" target=\"_blank\" rel=\"nofollow noopener\">react-native-aria packages<\/a> have been compromised on NPM, with the threat actors publishing a new version as recently as two hours ago.<\/p>\n<div style=\"text-align:center\">\n<figure class=\"image\" style=\"display:inline-block\"><img loading=\"lazy\" decoding=\"async\" alt=\"Ongoing compromise of NPM packages\" height=\"600\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/security\/g\/gluestack\/npm-supply-chain-attack\/gluestack-2-hours.jpg\" width=\"812\"\/><figcaption><strong>Ongoing compromise of NPM packages<\/strong><br \/><em>Source: BleepingComputer<\/em><\/figcaption><\/figure>\n<\/div>\n<p>The supply chain attack was discovered by cybersecurity firm <a href=\"https:\/\/www.aikido.dev\/\" target=\"_blank\" rel=\"nofollow noopener\">Aikido Security,<\/a> who discovered obfuscated code injected into the\u00a0<code>lib\/index.js<\/code>\u00a0file for the following packages:<\/p>\n<table align=\"center\" cellspacing=\"0\">\n<colgroup>\n<col span=\"2\"\/>\n<col\/><\/colgroup>\n<tbody>\n<tr>\n<td><strong>Package Name<\/strong><\/td>\n<p>&#13;<\/p>\n<td><strong>Version<\/strong><\/td>\n<p>&#13;<\/p>\n<td><strong>Weekly Downloads<\/strong><\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/button<\/td>\n<p>&#13;<\/p>\n<td>0.2.11<\/td>\n<p>&#13;<\/p>\n<td>51,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/checkbox<\/td>\n<p>&#13;<\/p>\n<td>0.2.11<\/td>\n<p>&#13;<\/p>\n<td>81,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/combobox<\/td>\n<p>&#13;<\/p>\n<td>0.2.10<\/td>\n<p>&#13;<\/p>\n<td>51,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/disclosure<\/td>\n<p>&#13;<\/p>\n<td>0.2.9<\/td>\n<p>&#13;<\/p>\n<td>3<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/focus<\/td>\n<p>&#13;<\/p>\n<td>0.2.10<\/td>\n<p>&#13;<\/p>\n<td>100,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/interactions<\/td>\n<p>&#13;<\/p>\n<td>0.2.17<\/td>\n<p>&#13;<\/p>\n<td>125,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/listbox<\/td>\n<p>&#13;<\/p>\n<td>0.2.10<\/td>\n<p>&#13;<\/p>\n<td>51,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/menu<\/td>\n<p>&#13;<\/p>\n<td>0.2.16<\/td>\n<p>&#13;<\/p>\n<td>22,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/overlays<\/td>\n<p>&#13;<\/p>\n<td>0.3.16<\/td>\n<p>&#13;<\/p>\n<td>96,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/radio<\/td>\n<p>&#13;<\/p>\n<td>0.2.14<\/td>\n<p>&#13;<\/p>\n<td>78,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/switch<\/td>\n<p>&#13;<\/p>\n<td>0.2.5<\/td>\n<p>&#13;<\/p>\n<td>477<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/toggle<\/td>\n<p>&#13;<\/p>\n<td>0.2.12<\/td>\n<p>&#13;<\/p>\n<td>81,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/utils<\/td>\n<p>&#13;<\/p>\n<td>0.2.13<\/td>\n<p>&#13;<\/p>\n<td>120,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>gluestack-ui\/utils<\/td>\n<p>&#13;<\/p>\n<td>0.1.17<\/td>\n<p>&#13;<\/p>\n<td>55,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/separator<\/td>\n<p>&#13;<\/p>\n<td>0.2.7<\/td>\n<p>&#13;<\/p>\n<td>65<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<tr>\n<td>react-native-aria\/slider<\/td>\n<p>&#13;<\/p>\n<td>0.2.13<\/td>\n<p>&#13;<\/p>\n<td>51,000<\/td>\n<p>&#13;<br \/>\n\t\t<\/tr>\n<\/tbody>\n<\/table>\n<p>These packages are very popular, with approximately 960,000 weekly downloads, making this a supply chain attack that could have widespread consequences.<\/p>\n<p>The malicious code is heavily obfuscated and is appended to the last line of source code in the file, padded with many spaces, so it&#8217;s not easily spotted when using the code viewer on the NPM site.<\/p>\n<div style=\"text-align:center\">\n<figure class=\"image\" style=\"display:inline-block\"><img loading=\"lazy\" decoding=\"async\" alt=\"Malicious code added to end of index.js file\" height=\"600\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/security\/g\/gluestack\/npm-supply-chain-attack\/gluestack-compromise.jpg\" width=\"980\"\/><figcaption><strong>Malicious code added to end of index.js file<\/strong><br \/><em>Source: BleepingComputer<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Aikido told BleepingComputer that the malicious code is nearly identical to a remote access trojan in <a href=\"https:\/\/www.aikido.dev\/blog\/catching-a-rat-remote-access-trojian-rand-user-agent-supply-chain-compromise\" target=\"_blank\" rel=\"nofollow noopener\">another NPM compromise they discovered<\/a> last month.<\/p>\n<p>The researcher&#8217;s analysis of the previous campaign\u00a0explains that the remote access trojan will connect to the attackers&#8217; command and control server and receive commands to execute.<\/p>\n<p>These commands include:<\/p>\n<ul style=\"list-style-type:square\">\n<li><strong>cd &#8211;\u00a0<\/strong>Change current working directory<\/li>\n<p>&#13;<\/p>\n<li><strong>ss_dir &#8211;\u00a0<\/strong>Reset directory to script\u2019s path<\/li>\n<p>&#13;<\/p>\n<li><strong>ss_fcd:<path>\u00a0<\/path><\/strong>&#8211; Force change directory to <path\/><\/li>\n<p>&#13;<\/p>\n<li><strong>ss_upf:f,d &#8211;\u00a0<\/strong>Upload single file f to destination d<\/li>\n<p>&#13;<\/p>\n<li><strong>ss_upd:d,dest &#8211;\u00a0<\/strong>Upload all files under directory d to destination dest<\/li>\n<p>&#13;<\/p>\n<li><strong>ss_stop &#8211;\u00a0<\/strong>Sets a stop flag to interrupt current upload process<\/li>\n<p>&#13;<\/p>\n<li><strong>Any other input &#8211;\u00a0<\/strong>Treated as a shell command, executed via child_process.exec()<\/li>\n<p>&#13;\n<\/ul>\n<p>The trojan also performs Windows PATH hijacking by prepending a fake Python path (%LOCALAPPDATA%\\Programs\\Python\\Python3127) to the PATH environment variable, allowing the malware to silently override legitimate python or pip commands to execute malicious binaries.<\/p>\n<p>Aikido sercurity researcher Charlie Eriksen has attempted to contact Gluestack about the compromise by creating <a href=\"https:\/\/github.com\/gluestack\/gluestack-ui\/issues\/2894\" target=\"_blank\" rel=\"nofollow noopener\">GitHub issues<\/a> on each of the project&#8217;s repositories, but there has not been any response at this time.<\/p>\n<p>&#8220;No response from package maintainers (it&#8217;s morning on a saturday in the US which is prob exactly why its happening now),&#8221; Arkido told BleepingComputer.<\/p>\n<p>&#8220;NPM we have contacted and reported each package, this is a process that usually takes multiple days for NPM to address though.&#8221;<\/p>\n<p>Aikido also attributes this attack to the same threat actors who compromised four other NPM packages earlier this week named\u00a0<em>biatec-avm-gas-station<\/em>,\u00a0<em>cputil-node<\/em>,\u00a0<em>lfwfinance\/sdk<\/em>, and\u00a0<em>lfwfinance\/sdk-dev<\/em>.<\/p>\n<p>BleepingComputer reached out to Gluestack about the compromised packages but has not received a reply at this time.<\/p>\n<div class=\"ia_ad\">\n<div class=\"ia_lef\">\n        <a href=\"https:\/\/www.tines.com\/access\/guide\/unlocking-it-agility-with-automation-patch-management\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=june-in-article-banner\" target=\"_blank\" rel=\"noopener sponsored\"><br \/>\n            <img decoding=\"async\" alt=\"Tines Needle\" src=\"https:\/\/www.bleepstatic.com\/c\/t\/tines\/tines-needle.jpg\" class=\"b-lazy\"\/><\/a>\n    <\/div>\n<div class=\"ia_rig\">\n<p>Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.<\/p>\n<p>In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work &#8212; no complex scripts required.<\/p>\n<p>        <button class=\"ia_button\"><a href=\"https:\/\/www.tines.com\/access\/guide\/unlocking-it-agility-with-automation-patch-management\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=june-in-article-banner\" target=\"_blank\" rel=\"noopener sponsored\">Get the free guide<\/a><\/button>\n    <\/div>\n<\/div><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A significant supply chain attack hit NPM after 16\u00a0popular Gluestack &#8216;react-native-aria&#8217; packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT). BleepingComputer determined that the compromise began on June 6 at 4:33 PM EST, when a new version of the\u00a0react-native-aria\/focus package was published to NPM.\u00a0Since [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":281176,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[101235],"tags":[110507,2394,917,34454,110506,15047,29205,33465,2908,6039],"dealstore":[],"offerexpiration":[],"class_list":["post-281175","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-960k","tag-attack","tag-chain","tag-downloads","tag-gluestack","tag-hits","tag-npm","tag-packages","tag-supply","tag-weekly"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Supply chain attack hits Gluestack NPM packages with 960K weekly downloads - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=281175\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"A significant supply chain attack hit NPM after 16\u00a0popular Gluestack &#8216;react-native-aria&#8217; packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT). BleepingComputer determined that the compromise began on June 6 at 4:33 PM EST, when a new version of the\u00a0react-native-aria\/focus package was published to NPM.\u00a0Since [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=281175\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-08T09:35:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=281175#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=281175\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads\",\"datePublished\":\"2025-06-08T09:35:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=281175\"},\"wordCount\":568,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=281175#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg\",\"keywords\":[\"960K\",\"Attack\",\"Chain\",\"Downloads\",\"Gluestack\",\"Hits\",\"NPM\",\"packages\",\"Supply\",\"Weekly\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=281175#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=281175\",\"url\":\"https:\/\/fivemor.com\/?p=281175\",\"name\":\"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=281175#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=281175#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg\",\"datePublished\":\"2025-06-08T09:35:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=281175#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=281175\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=281175#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg\",\"width\":1600,\"height\":900},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=281175#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=281175","og_locale":"en_US","og_type":"article","og_title":"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads - Som2ny Network","og_description":"A significant supply chain attack hit NPM after 16\u00a0popular Gluestack &#8216;react-native-aria&#8217; packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT). BleepingComputer determined that the compromise began on June 6 at 4:33 PM EST, when a new version of the\u00a0react-native-aria\/focus package was published to NPM.\u00a0Since [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=281175","og_site_name":"Som2ny Network","article_published_time":"2025-06-08T09:35:07+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=281175#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=281175"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads","datePublished":"2025-06-08T09:35:07+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=281175"},"wordCount":568,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=281175#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg","keywords":["960K","Attack","Chain","Downloads","Gluestack","Hits","NPM","packages","Supply","Weekly"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=281175#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=281175","url":"https:\/\/fivemor.com\/?p=281175","name":"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=281175#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=281175#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg","datePublished":"2025-06-08T09:35:07+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=281175#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=281175"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=281175#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/06\/npm.jpg","width":1600,"height":900},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=281175#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Supply chain attack hits Gluestack NPM packages with 960K weekly downloads"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/281175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=281175"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/281175\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/281176"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=281175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=281175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=281175"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=281175"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=281175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}