<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/sophisticated-supply-chain-attack-malicious-npm-packages-use-image-files-to-hide-backdoor-code-llnmf675w" -->

---
title: Sophisticated Supply Chain Attack: Malicious npm...
description: Cybersecurity researchers discovered malicious packages in the npm registry on 13 July 2024. These packages disguised as legitimate software used JPG image...
canonical: https://daily.dev/posts/sophisticated-supply-chain-attack-malicious-npm-packages-use-image-files-to-hide-backdoor-code-llnmf675w
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Sophisticated Supply Chain Attack: Malicious npm Packages Use Image Files to Hide Backdoor Code | daily.dev
og:description: Cybersecurity researchers discovered malicious packages in the npm registry on 13 July 2024. These packages disguised as legitimate software used JPG image...
og:url: https://daily.dev/posts/sophisticated-supply-chain-attack-malicious-npm-packages-use-image-files-to-hide-backdoor-code-llnmf675w
og:image: https://api.daily.dev/og/posts/llNmf675w.png
og:image:alt: Sophisticated Supply Chain Attack: Malicious npm Packages Use Image Files to Hide Backdoor Code
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Sophisticated Supply Chain Attack: Malicious npm Packages Use Image Files to Hide Backdoor Code

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Cybersecurity researchers discovered malicious packages in the npm registry on 13 July 2024. These packages disguised as legitimate software used JPG image files to hide command and control functionalities, making it difficult for conventional detection mechanisms to identify them. Two fake AWS packages were highlighted, having been downloaded 182 times before removal, indicating a delay in detection. This incident emphasizes the need for enhanced vigilance and improved detection capabilities to protect against sophisticated supply chain attacks in open-source ecosystems.

## Content

# Malicious Packages Using Image Files Discovered in NPM Registry

On 13 July 2024, cybersecurity researchers from Phylum identified malicious packages in the npm registry disguised as legitimate software. These packages embedded command and control functionalities within image files, which were executed during installation.

## Attack Details

The identified payloads in these packages registered the infected machines with an attack server. Following registration, the compromised systems were capable of fetching and executing commands from the server and then transmitting the results back to the attackers. The specific method used involved hiding the backdoor code within JPG image files that got processed during installation.

## Sophisticated Techniques

This incident is notable due to the sophistication of the tactics employed. By concealing malicious code in image files, attackers were able to avoid conventional detection mechanisms. The attackers specifically targeted open-source ecosystems, posing significant risks to developers and highlighting a growing trend of exploiting open-source repositories.

## Impact and Response

Two fake AWS packages on npm were particularly highlighted in the research. These packages mimicked a legitimate library, misleading developers and compromising systems. Before their removal, these malicious packages were downloaded 182 times combined, indicating a delayed detection and response issue.

## Call for Vigilance

This incident underscores the need for heightened vigilance and improved detection capabilities among developers and security organizations. The growing volume and sophistication of such supply chain attacks necessitate robust security practices and ongoing awareness to protect against potential threats in open-source ecosystems.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#open-source](https://daily.dev/tags/open-source), [#malware](https://daily.dev/tags/malware), [#npm](https://daily.dev/tags/npm), [#supply-chain](https://daily.dev/tags/supply-chain)

[View this post on daily.dev](https://daily.dev/posts/sophisticated-supply-chain-attack-malicious-npm-packages-use-image-files-to-hide-backdoor-code-llnmf675w)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Sophisticated Supply Chain Attack: Malicious npm Packages Use Image Files to Hide Backdoor Code","url":"https://daily.dev/posts/sophisticated-supply-chain-attack-malicious-npm-packages-use-image-files-to-hide-backdoor-code-llnmf675w","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/sophisticated-supply-chain-attack-malicious-npm-packages-use-image-files-to-hide-backdoor-code-llnmf675w"},"datePublished":"2024-07-16T15:24:50.278Z","dateModified":"2024-07-18T11:00:59.067Z","description":"Cybersecurity researchers discovered malicious packages in the npm registry on 13 July 2024. These packages disguised as legitimate software used JPG image...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/03f9788154e0557e8c52bdbb9781a1c3?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/03f9788154e0557e8c52bdbb9781a1c3?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/sophisticated-supply-chain-attack-malicious-npm-packages-use-image-files-to-hide-backdoor-code-llnmf675w","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,open-source,malware,npm,supply-chain","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Sophisticated Supply Chain Attack: Malicious npm Packages Use Image Files to Hide Backdoor Code"}]}
```

