Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Snyk: Critical NPM Supply Chain Attack Response Guide

Snyk
06/17/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


treat that environment as compromised. Check for that router underscore init dot js file in the tarball before assuming you are clean. 2. The remediation order matters. Kill the dead man switch and remove editor persistent hooks before you rotate any credentials. Revoking first risks triggering home directory destruction. And 3. Two settings protect you against this entire class of attack going forward. Set minimum release age to 7 in your npmrc configuration file and pin your oidc trusted publisher config to a specific branch and workflow file, not just a repository. The full indicators of compromise list, all the detection scripts, and the sneak security database entry for this campaign are linked in the description below.

TL;DR

  • Any environment that installed et10 stack/router family packages on May 11th should be treated as compromised and checked for the router_init.js file in the tarball
  • Remediation must follow a specific order: disable the dead man switch and remove persistent hooks before rotating credentials to prevent triggering home directory destruction
  • Two configuration changes provide protection: set minimum NPM release age to 7 days and pin OIDC trusted publisher config to specific branch and workflow file

Summary

This urgent security advisory addresses a critical supply chain attack targeting the et10 stack/router family of NPM packages on May 11th. The video provides immediate response guidance for potentially compromised environments, emphasizing the importance of proper remediation sequencing to prevent data loss. Key protective measures include implementing a 7-day minimum release age in NPM configurations and restricting OIDC trusted publisher settings to specific branches and workflow files rather than entire repositories. The guidance is particularly relevant for development teams using affected packages in production environments, as the attack included sophisticated persistence mechanisms and destructive capabilities that could be triggered by premature credential rotation.

Chapters

0:00 - Compromise Assessment
0:09 - Remediation Sequence
0:23 - Preventive Configuration
0:37 - Additional Resources

Key Quotes

0:00 "If you installed any et10 stack slash router family package on May 11th, treat that environment as compromised."
0:15 "The remediation order matters. Kill the dead man switch and remove editor persistent hooks before you rotate any credentials."
0:27 "Set minimum release age to 7 in your npmrc configuration file and pin your oidc trusted publisher config to a specific branch and workflow file, not just a repository."

FAQ

How do I check if my environment was affected by the et10 stack/router attack?

Check for the router_init.js file in the tarball of any et10 stack/router family packages installed on May 11th. If present, treat that environment as compromised and follow the remediation steps in the proper sequence.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • DevSecOps
  • Threat Intelligence
  • Technical Deep Dive
  • Best Practices
  • Supply Chain Security
  • NPM Package Security
  • Incident Response
  • Credential Management
  • OIDC Configuration
  • Malware Remediation
  • Package Registry Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Snyk: Critical NPM Supply Chain Attack Response Guide

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Era of Public AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Era of Public AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-public-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-revolutionizing-identity-attacks-same-tactics-enhanced-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version