Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Snyk: Critical NPM Supply Chain Attack Response Guide

Snyk
06/17/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


treat that environment as compromised. Check for that router underscore init dot js file in the tarball before assuming you are clean. 2. The remediation order matters. Kill the dead man switch and remove editor persistent hooks before you rotate any credentials. Revoking first risks triggering home directory destruction. And 3. Two settings protect you against this entire class of attack going forward. Set minimum release age to 7 in your npmrc configuration file and pin your oidc trusted publisher config to a specific branch and workflow file, not just a repository. The full indicators of compromise list, all the detection scripts, and the sneak security database entry for this campaign are linked in the description below.

TL;DR

  • Any environment that installed et10 stack/router family packages on May 11th should be treated as compromised and checked for the router_init.js file in the tarball
  • Remediation must follow a specific order: disable the dead man switch and remove persistent hooks before rotating credentials to prevent triggering home directory destruction
  • Two configuration changes provide protection: set minimum NPM release age to 7 days and pin OIDC trusted publisher config to specific branch and workflow file

Summary

This urgent security advisory addresses a critical supply chain attack targeting the et10 stack/router family of NPM packages on May 11th. The video provides immediate response guidance for potentially compromised environments, emphasizing the importance of proper remediation sequencing to prevent data loss. Key protective measures include implementing a 7-day minimum release age in NPM configurations and restricting OIDC trusted publisher settings to specific branches and workflow files rather than entire repositories. The guidance is particularly relevant for development teams using affected packages in production environments, as the attack included sophisticated persistence mechanisms and destructive capabilities that could be triggered by premature credential rotation.

Chapters

0:00 - Compromise Assessment
0:09 - Remediation Sequence
0:23 - Preventive Configuration
0:37 - Additional Resources

Key Quotes

0:00 "If you installed any et10 stack slash router family package on May 11th, treat that environment as compromised."
0:15 "The remediation order matters. Kill the dead man switch and remove editor persistent hooks before you rotate any credentials."
0:27 "Set minimum release age to 7 in your npmrc configuration file and pin your oidc trusted publisher config to a specific branch and workflow file, not just a repository."

FAQ

How do I check if my environment was affected by the et10 stack/router attack?

Check for the router_init.js file in the tarball of any et10 stack/router family packages installed on May 11th. If present, treat that environment as compromised and follow the remediation steps in the proper sequence.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • DevSecOps
  • Threat Intelligence
  • Technical Deep Dive
  • Best Practices
  • Supply Chain Security
  • NPM Package Security
  • Incident Response
  • Credential Management
  • OIDC Configuration
  • Malware Remediation
  • Package Registry Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Snyk: Critical NPM Supply Chain Attack Response Guide

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version