Researchers linked a threat actor tracked as RED-LILI to a large-scale software supply chain attack that pushed nearly 800 malicious packages to the npm registry in a burst of activity over roughly a week. Checkmarx reported the operation began around February 23, 2022, and relied on a highly automated pipeline that created a separate npm account for each package, complicating bulk detection and takedown efforts. The campaign used custom Python tooling, Selenium, and the open-source Interactsh project to automate account creation and bypass npm email one-time-password verification during signup.
The malicious packages were part of a broader effort to compromise developers and downstream environments through common package ecosystem abuse techniques, including typosquatting and dependency confusion. Reporting tied the activity to packages crafted to target organizations such as Azure, Uber, and Airbnb, underscoring how attackers can industrialize package publication at scale and turn open-source repositories into an efficient delivery channel for supply chain compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Checkmarx said the earliest evidence of anomalous activity tied to the RED-LILI-linked NPM supply chain campaign was observed on February 23, 2022. The operation involved automated creation of separate NPM accounts for malicious package publication.
Checkmarx publicly analyzed the large-scale campaign and described the attacker’s automated workflow using custom Python, Selenium, and Interactsh to bypass NPM signup OTP verification and publish malicious packages. The report linked the activity to dependency confusion and typosquatting targeting developers associated with Azure, Uber, and Airbnb.
After the initial activity was observed, the attacker published nearly 800 malicious NPM packages in bursts over roughly a week. The packages were distributed across one account per package to hinder bulk detection and takedown.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
docs.npmjs.com
Open sourcethehackernews.com
Open sourcecheckmarx.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.