Josh Junon

@bad-at-computer.bsky.social

Coding @ github.com/qix-, making an operating system @ github.com/oro-os

Finally figured out that JLCPCB mis-fabricated the board. Required me to file off a bunch of edge plating and cut some pieces off but ultimately got #firmware flashed. All in #rust, if you can believe it. Tomorrow will be the rest of the LEDs (on the back), testing ULPI, OLED and Ethernet.

debug: CVE-2025-59144 error-ex: CVE-2025-59330 color-string: CVE-2025-59142 backslash: CVE-2025-59140 is-arrayish: CVE-2025-59331 simple-swizzle: CVE-2025-59141 color: CVE-2025-59143 color-convert: CVE-2025-59162 color-name: CVE-2025-59145 <pending publication> Chalk pkgs still pending; bear with.

I have the NPM logs. Not much unexpected except an IP address that wasn't previously known. It seems clear it was indeed an MITM via the known IP that's out there, followed by account actions via a private IPv6 address.

All packages have been published over. Please let me know if I broke you somehow and I'll get it fixed ASAP. Security advisories drafted and CVEs requested; not sure if they should be published immediately without the CVE yet so have held off until I get some guidance (or they're alloc'd).

Post mortem is still on hold until I can get everyone secure again. Npm has not been helpful and I'm currently blocked. I'm sorry for the continued delay, I'd like to be done with this more than anyone else, believe me.

Does anyone have a contact at npm who can contact me directly? This is getting silly. Non sequiturs and hours between responses is so unprofessional I'm getting irritated. People are still affected by cached versions with malware and once again there's nothing I can do to help them.

Hi, something still isn't right with my account configuration. Going to hold off on the package updates until I can receive a response from npm. There is no threat or continued breach, but I'm not able to publish in a way I'm confident will be secure quite yet. Please bear with.

⚠️ Heads Up: New patch versions of all affected repositories will be going out today. Please expect that. Will start in the next hour and will be taking things very slowly. Chalk repositories are not included in this, as Sindre has already taken care of them. I am terrified, lmk if I mess up.

I feel as though I should write a runbook for other maintainers who are in this situation to help guide them through the process of dealing with a situation like this. Thinking back, I realize now that "what's next" was the prevailing unanswered question at several points throughout it.

Post-mortem to come tomorrow, along with publishing a new version for all affected packages to help cache-bust some of you on e.g. private registries or mirrors. Thank you all again for the patience and for the kindness.

Hi everyone. The 'next day' busy-ness has fully set in. Since I still haven't gotten any followup from npm regarding account actions taken, and given that I have now been approached by authorities, I will need to hold off on the post-mortem for a day or two. Sincerest apologies for the delay.

NPM account restored. My packages should be back to normal; going to do a quick skim to make sure before calling it a day. NPM doesn't show audit logs so unfortunately it's on them to release any information I haven't already given myself. Post-mortem to come tomorrow. Thank you everyone <3

For anyone who has checks or can otherwise use this information: I won't be publishing anything over the next 48 hours minimum, probably the next week. Still have not regained access though npm is starting to help with that.

NPM is now working to restore my access to the account. Will need to take a break for the evening now that things have settled and I've been in pain all day. Will begin a full retro and post-mortem tomorrow (sorry for the delay). Feel free to send any Q's my direction in the meantime.

Yes, there's at least one other confirmed package that's been hit. I would imagine I'm probably the first / 'loudest' that has been affected, but despite thinking so earlier I don't think this was targeted. They must have filtered based on download count or something to choose which packages to hit.

Brian Fox@brianfox.bsky.social · 11mo ago

Our malware systems at Sonatype seem to be picking these up coming from other, not yet reported accounts. This attack seems to have landed more publishers as this unfolds. Check your accounts folks while we work with others to contain.

Message from NPM: "All impacted package versions have been taken down. I'll be in touch when we have more information regarding account recovery." I've requested further information about which packages were published, their versions, and all account actions NPM took.

Looks like things are being taken down slowly, but please stay vigilant; I have no control over what's happening to my account right now, nor any info. It's not clear if npm has taken complete control over it or not. They are not communicating with me whatsoever. Access has not been re-established.