Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› ua-parser-js npm Hijack 2021: How a Taken-Over Publishing…
Breach analysis Incident: 22 Oct 2021

ua-parser-js npm Hijack 2021: How a Taken-Over Publishing Account Shipped a Cryptominer and Password Stealer

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: NHI
On this page

On 22 October 2021, an attacker took over the npm account that publishes ua-parser-js, a JavaScript library for reading browser user-agent strings with millions of weekly downloads, and released three malicious versions: 0.7.29, 0.8.0 and 1.0.0. Anyone who installed them during a window of about four hours ran a script that downloaded a Monero cryptominer on Linux and Windows and, on Windows, a trojan that stole stored passwords. The maintainer, Faisal Salman, said: "I believe someone was hijacking my npm account." He published clean versions 0.7.30, 0.8.1 and 1.0.1 within hours, and GitHub and CISA issued advisories the same day. GitHub warned that any machine that installed the bad versions "should be considered fully compromised." How the account was taken over has not been confirmed. Three weeks later GitHub named this case when it announced mandatory two-factor authentication for maintainers of popular npm packages.

Key takeaways

  • Malicious ua-parser-js versions 0.7.29, 0.8.0 and 1.0.0 were published from the maintainer's hijacked npm account on 22 October 2021 and were available for about four hours, according to Rapid7.
  • The package had nearly 8 million weekly downloads according to Rapid7, or six to seven million according to The Record, so even a short window reached many build systems.
  • The payload installed an XMRig Monero miner on Linux and Windows and, on Windows, a password-stealing DLL, according to CERT-EU.
  • GitHub advised treating affected machines as fully compromised and rotating all secrets on them; it later cited this case in announcing 2FA enforcement for top npm packages.
  • The identity lesson: a package publishing account is a non-human trust anchor for every downstream build, and protecting it with a password alone hands that trust to whoever gets the password.

At a glance

Organisationua-parser-js (maintainer Faisal Salman) and developers and organisations that installed it
When22 October 2021, from about 12:15 to about 16:26 GMT
AttackerUnknown; Rapid7 found a hacking forum offer of an npm account matching the package's profile but no definitive link
Entry pointTakeover of the maintainer's npm publishing account
Identities abusedThe npm account and publishing rights for ua-parser-js; passwords and credentials on infected machines were then targeted
ImpactThree malicious releases installing a cryptominer and, on Windows, a password stealer on machines that installed them in the window
CategoryNHI. Incident class: confirmed NHI breach (hijacked npm publishing account used to ship credential-stealing malware)

What happened

ua-parser-js is a small library that turns browser user-agent strings into device, browser and operating system details. It is a dependency of many larger projects, which is why it was downloaded millions of times a week. On Friday 22 October 2021, three new versions appeared on npm, one on each release line. According to Rapid7, they were downloadable from about 12:15 GMT until between 16:16 and 16:26 GMT that day.

The new versions carried a preinstall script that ran automatically during installation. CERT-EU's analysis describes what it did. On Linux, if the device was not located in Russia, Ukraine, Belarus or Kazakhstan, it downloaded a file called jsextension, an XMRig Monero miner. On Windows, a batch file downloaded the same miner and also a DLL. "This DLL is a password-stealing trojan that will try to steal the passwords stored on the device," CERT-EU wrote. The Record reported that the Windows infostealer could export browser cookies, browser passwords and operating system credentials, and might be a Danabot variant.

Users spotted the bad releases quickly. Salman told users, as quoted by The Record, "I believe someone was hijacking my npm account," and published clean versions 0.7.30, 0.8.1 and 1.0.1. GitHub's advisory, published the same day, said: "Any computer that has this package installed or running should be considered fully compromised." It added: "All secrets and keys stored on that computer should be rotated immediately from a different computer." CISA issued its own alert late that Friday night, according to The Record.

How the attacker got into the account is still unknown. Rapid7's IntSights team found a thread created on 5 October 2021 on a Russian hacking forum, in which a seller offered a developer account for an unnamed npm package with about 7 million weekly installations for $20,000, noting it "does not have 2-factor authentication." Rapid7 said the figures matched but there was no definitive link. Thirteen days later, almost identical malicious code appeared in the coa and rc hijacks. On 15 November GitHub's chief security officer Mike Hanley cited both cases, writing that "At times, these account takeover (ATO) events have involved npm accounts where two-factor authentication was not enabled," and announced 2FA enforcement for maintainers of top packages from early 2022.

Timeline

DateEvent
5 October 2021A seller on a Russian hacking forum offers access to an unnamed npm developer account without 2FA, according to Rapid7; no confirmed link to ua-parser-js.
22 October 2021Malicious versions 0.7.29, 0.8.0 and 1.0.0 are published at about 12:15 GMT and removed about four hours later; clean versions follow.
22 October 2021GitHub publishes its advisory and CISA issues an alert.
23 October 2021The Record reports the hijack and the password-stealing payload.
26 October 2021CERT-EU publishes its advisory with the payload analysis.
15 November 2021GitHub cites ua-parser-js, coa and rc and announces 2FA enforcement for top npm maintainers.

How it happened: the identity attack path

  1. Publishing account taken over. The attacker gained control of the npm account that publishes ua-parser-js; the method has not been confirmed, and GitHub has said some takeovers of this period involved accounts without 2FA.
  2. Malicious releases published. Using the account's publishing rights, the attacker released three new versions that npm and downstream projects treated as genuine.
  3. Automatic installation. Projects with version ranges that accepted the new releases pulled them into developer machines and build pipelines, where a preinstall script ran.
  4. Payload and credential theft. The script installed an XMRig miner and, on Windows, a trojan that harvested stored passwords and credentials.
  5. Revocation and recovery. The maintainer regained control and published clean versions; affected machines needed full secret rotation.

Impact

  • Confirmed: three malicious versions were published and available for about four hours; machines that installed them received a cryptominer and, on Windows, a password stealer.
  • Scale: no count of affected installations has been published; exposure was limited to systems that installed or built with the package during the window, according to Rapid7.
  • Credentials at risk: passwords, browser cookies and other secrets stored on infected Windows machines, including any developer or CI credentials present.
  • Wider: the incident, with coa and rc, fed directly into GitHub's decision to require 2FA for maintainers of popular npm packages.

What this means for NHI and AI agent security

An npm publishing account is not just a person's login. It is the identity that the registry, and every project that depends on the package, trusts to say "this release is genuine". When it is taken over, the attacker inherits that trust and every automated build that pulls new versions without review. We treat these takeovers as NHI breaches because the abused identity is a publishing credential acting for a software artefact, and because the payload went straight for the credentials stored on developer and build machines.

The same pattern runs through our breach database, from the eslint-scope compromise of 2018 to the Shai-Hulud worm. The defences are the same too: strong authentication and short-lived tokens for publishing, trusted publishing from CI rather than personal machines, lockfiles that stop surprise upgrades, and rotation of secrets on any machine that installed a bad version. Our CI/CD Pipeline Identity Security Guide and Token and Session Security Guide go further.

Recommendations

  • Rotate every secret on machines that installed a malicious version. Follow GitHub's advice and rotate from a different, clean computer. See the Leaked Credential Response Playbook.
  • Protect publishing accounts with phishing-resistant MFA. Require 2FA for publishing and account changes on every registry account. See our MFA Guide.
  • Publish from CI with short-lived, scoped credentials. Trusted publishing ties releases to a pipeline identity instead of a long-lived personal token. See our CI/CD Pipeline Identity Security Guide.
  • Pin dependencies and review new releases. Lockfiles and a cooling-off period for new versions stop an automatic pull of a release that is only hours old.
  • Restrict install scripts in builds. Disable or allow-list preinstall and postinstall scripts so a dependency cannot run code on install by default.
  • Keep long-lived credentials off developer and build machines. Secrets that are not stored locally cannot be harvested by an infostealer. See our Secrets Management Guide.

Frequently asked questions

Which ua-parser-js versions were malicious?

Versions 0.7.29, 0.8.0 and 1.0.0, published on 22 October 2021, contained malware. The clean replacements are 0.7.30, 0.8.1 and 1.0.1. Anyone who installed a malicious version should treat the machine as compromised and rotate its secrets.

What did the ua-parser-js malware do?

A preinstall script downloaded an XMRig Monero cryptominer on Linux and Windows. On Windows it also installed a password-stealing trojan that harvested passwords and credentials stored on the device, according to CERT-EU and The Record.

How was the ua-parser-js npm account hijacked?

That has not been confirmed. The maintainer said someone was hijacking his npm account. Rapid7 found a forum offer of an npm account without 2FA matching the package's profile, but no definitive link, and GitHub said some takeovers in this period involved accounts without two-factor authentication.

coa and rc npm Hijacks 2021 · eslint-scope npm Compromise 2018 · Shai-Hulud npm Worm 2025 · CI/CD Pipeline Identity Security Guide · MFA Guide

How NHI Mgmt Group can help

Package publishing accounts and the build machines that consume packages are both full of non-human credentials. We help teams secure publishing identities, move to short-lived pipeline credentials and plan the rotation work when a dependency turns malicious. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org