Back to news

Rogue npm Packages and a Four-Year Android Botnet Expose Supply Chain Risks

Two separate investigations reveal how attackers are hiding malicious code inside developer tools and consumer hardware to conduct fraud and espionage at scale.

Rogue npm Packages and a Four-Year Android Botnet Expose Supply Chain Risks

What happened

Security researchers flagged three npm packages masquerading as legitimate PostCSS utilities — postcss-minify-selector, postcss-minify-selector-parser, and aes-decode-runner-pro — that collectively racked up more than a thousand downloads before being identified. Each package was designed to quietly install a Windows remote access trojan, granting attackers persistent control over infected developer machines. Separately, investigators from multiple cybersecurity firms traced the Popa botnet — an Android-based network active for at least four years — to NetNut, a residential proxy service run by the publicly traded Israeli company Aladdin. Popa is alleged to have conscripted millions of consumer TV boxes worldwide into relaying traffic for ad fraud, credential-stuffing campaigns, and large-scale data scraping operations.

Why it matters for your business

The npm incident is a textbook software supply chain attack: developers searching for familiar-sounding utility packages can inadvertently introduce a persistent backdoor into their build pipelines, which then propagates to any product or service built on that code. Engineering and security teams should enforce package-integrity checks, pin dependency versions, and audit new or low-download packages before allowing them into CI/CD workflows. The Popa case raises a different but equally pressing concern — devices that employees or customers use at home, including inexpensive Android TV boxes, can be conscripted into criminal infrastructure without the owner's knowledge. Organizations that allow personal or third-party devices on corporate networks, or that operate consumer-facing hardware fleets, face real exposure if those endpoints are silently proxying hostile traffic. The link to a publicly traded company also signals that the line between legitimate proxy services and botnet-powered fraud networks is increasingly difficult to distinguish at the procurement stage.

What to watch next

Regulators and npm's maintainers are likely to face renewed pressure to tighten vetting procedures for newly published packages, particularly those mimicking high-trust namespaces like PostCSS. On the Popa front, law enforcement scrutiny of NetNut and its parent company Aladdin could set a precedent for how securities and cybercrime law applies to publicly listed firms whose infrastructure is allegedly weaponized for fraud. Both cases will test how quickly the broader industry can close the gap between attacker publication speed and defensive detection.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp