IncidentTwo npm Packages Turned Data Thieves Through Compromised Maintainer Credentials
What Happened On March 19, 2026, Sonatype Security Research reported two malicious npm packages—sbx-mask and touch-adv—to npm s maintainers. These packages were published through a compromised trusted














