---
title: "Vulnerable npm API exposes Private Packages, Why You Need to be Aware of it! | DuoCircle"
description: "The past few years saw a rise in the variety and volume of software supply chain attacks."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/"
---

Quick Answer

Aqua Security researchers disclosed a timing attack against the npm registry API (registry.npmjs.org) that exposes the names of organizations' private packages. The vulnerability exploits response time differences: the registry returns HTTP 404 faster for non-existent package names than for private ones the requester is not authorized to see. By comparing response times across a list of guessed package names, an attacker enumerates which private packages exist in a target organization. Once private package names are known, attackers publish public packages with the same name on npm and wait for misconfigured CI systems or developer machines to pull the public version (a dependency confusion attack), achieving code execution in the target's build pipeline. Mitigations: scoped package names, configuring package managers to prefer the private registry, lockfile integrity checks, and SBOM audits.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Vulnerable%20npm%20API%20exposes%20Private%20Packages%2C%20Why%20You%20Need%20to%20be%20Aware%20of%20it!&url=undefined%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F&title=Vulnerable%20npm%20API%20exposes%20Private%20Packages%2C%20Why%20You%20Need%20to%20be%20Aware%20of%20it! "Share on Reddit") [ ](mailto:?subject=Vulnerable%20npm%20API%20exposes%20Private%20Packages%2C%20Why%20You%20Need%20to%20be%20Aware%20of%20it!&body=Check out this article: undefined%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F "Share via Email") 

![Vulnerable npm API](https://media.mailhop.org/duocircle/images/2022/10/SPF-record-checker-3896.jpg) 

_The past few years saw a rise in the variety and volume of **software supply chain attacks**. The threat landscape is evolving too fast to neglect the latest updates. The article shows how researchers discovered an npm [API vulnerability.](https://www.reflectiz.com/blog/common-api-vulnerabilities/)_

_that reminds developers to stay on top of their security practices._

Aqua researchers recently discovered a novel timing attack against the **npm’s registry API** that hackers can exploit to potentially [expose](https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm) private packages used by organizations, putting them at risk of supply chain threats. The attackers leverage the time npm API (registry. npmjs\[.\]org) takes to return the “HTTP 404” error message when a user queries for a private package.

In the scoped confusion attack, the threat attackers compare the response time with the one for a non-existing module. The cybercriminals’ ultimate motive is to **identify packages** that organizations use internally, create their public versions, and attempt to compromise the software supply chain.

## Why Do Developers House Code Dependencies on npm?

The internal developer projects mostly use standard, trusted code dependencies housed in private repositories on npm, PyPi, etc. The developers do it to prevent code dependency issues and software supply chain attacks and to protect the **sensitive internal developer code**.

However, if cyber criminals manage to hijack or weaponize them, the code repositories provide an attractive avenue for [threat actors](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/) looking to crack organizational networks and access sensitive information. A timing attack helps cybercriminals launch **malicious code attacks** at corporate targets by cloning private package names.

## How the Latest Timing Attack is Different From Dependency Confusion Attacks

The latest findings about the npm API confirm that the attack differs from [dependency confusion attacks](https://fossa.com/blog/dependency-confusion-understanding-preventing-attacks/#:~:text=Dependency%20confusion%20is%20a%20software,a%20package%20before%20private%20registries.) because it requires the threat actors to guess the private package names used by an enterprise and then publish **malicious packages** with the same name available to the public.

In contrast, dependency confusion attacks (or namespace confusion) rely on package managers checking and confirming **public code registries** for a package before private registries, helping them retrieve a higher malicious version package from the public repository.

## Leveraging Sophisticated Search Methods for Private Package Names

> “If a hacker sends about five consecutive requests for information concerning a private package and analyzes the time taken to get a reply from npm, it is possible for him to identify whether the private package exists.”

According to the research, there are a few methods that threat actors can use to create a list of private package names and test them with the timing attack. These include:

- They can utilize the patterns found in the organization’s public package nomenclature and perform a [dictionary attack](https://www.techtarget.com/searchsecurity/definition/dictionary-attack) to guess the names of the private packages.
- They can **utilize online public data sets** (like libraries.io) and access historical information about the deleted public packages that the organizations converted to private ones.

The **Aqua Security team** disclosed the npm bug to the Microsoft-owned subsidiary GitHub on March 8, 2022\. However, GitHub responded that the timing attack would not get fixed due to architectural limitations.

[![Attack](https://media.mailhop.org/duocircle/images/2022/10/spf-record-8862.jpg)](https://media.mailhop.org/duocircle/images/2022/10/spf-record-8862.jpg)

> “Because of the architectural limitations, we cannot stop [timing attacks](https://www.itbusiness.ca/news/timing-attack-could-affect-millions-of-web-users/15359) from determining if a specific private package exists on npm,” GitHub explained to Aqua Security.

Thus, the researchers say that the responsibility to take preventive action lies with the organizations, who can frequently search npm for malicious packages that **spoof their private packages** with similar or duplicate names.

## A Risky Time for Dependencies in the Software Supply Chain

The software supply chain is crucial to the applications and websites’ lifecycle. The common interdependencies and components in modern software development infrastructure can increase the attack surface and allow threat actors to **bypass robust security layers IT teams** add to their infrastructure.

Only one vulnerability in the code base is enough to compromise the entire software supply chain. The primary issue is that current projects have numerous dependencies. Additionally, software development relies heavily on third-party vendors and **open-source platforms** because it speeds up the process, offering developers standard libraries. Since many organizations or people maintain the code, it becomes challenging to prevent security flaws.

## Steps Organizations Can Take to Protect Themselves

Here are tips for businesses to mitigate the risks:

- Gather a list of all the organization’s public and private packages on all the package management platforms.
- Actively look for [typosquatting](https://www.kaspersky.com/resource-center/definitions/what-is-typosquatting), masquerading packages, or lookalikes. Verify that no packages have the same name as the organization’s internal private packages.
- If you discover similar packages, ensure they **do not contain malware** and notify the relevant stakeholders immediately.
- If there are no public packages similar to the organization’s internal packages, you can create public packages as placeholders to mitigate such threats.
- To prevent any typosquatting attacks, you can **register a public registry** with the private registry’s name.
- Organizations must use a stricter vendor policy (e.g., using the exact version number, not **“\*”** or **“^”** to prevent silent updates during installations).
- The owner or maintainer of a package must enable [multi-factor authentication](https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA).
- Developers must never deploy sourcemaps and configuration files in production.
- They must keep all the dependencies updated.

[![Cybersecurity](https://media.mailhop.org/duocircle/images/2022/10/spf-record-check-6328.jpg)](https://media.mailhop.org/duocircle/images/2022/10/spf-record-check-6328.jpg)

## What Security Researchers Have to Say

- #### _Yakir Kadkoda, Aqua Security researcher_

> “The threat actors can create a potential package names list and detect the organizations’ scoped private packages. Then, they can masquerade public packages and trick users and employees into downloading them.”

He further explained that it takes less time, on average, to get a **reply for a non-existent package** than for an existing one. “If you don’t find public packages resembling your internal packages, consider creating placeholder public packages to prevent such attacks,” Kadkoda said.

- #### _Lance Vick, security consultant_

On software supply chain vulnerabilities, he commented that as a developer, if you don’t maintain a code, you cannot control it, and most of your project’s code is not your code these days. However, few developers understand that they **must review the code** copied from the internet (written by strangers) with the same scrutiny, if not higher, as the code written by employees.

> “The reality is most organizations trust code written by strangers more than their employees, and it causes embarrassing headlines,” he remarked.

- #### _Nusrat Zahan, corresponding author of a_ [_Preprint study_](https://regmedia.co.uk/2022/08/12/openssfscorecards%5Fpaper.pdf) _and a doctoral student at North Carolina State University_

“Packages may include more than the listed vulnerabilities.” For example, some studies show how researchers found 95 times more vulnerabilities than reported. Hence, if we perform **in-depth studies** for detecting vulnerabilities, we can find more than we know, and in such a case, we believe we need to focus on secure coding.

> “Note that the scorecard tool mentioned in our study gives us a way of measuring the **security practices**, but it is up to the organizations to determine how they can improve their package security.”

## Final Words

Cybercriminals often seek unique ways to penetrate your organization. Recent years have seen a significant increase in software supply chain attacks. Developers have many tools to help keep their software supply chain safe. However, in the above case, as **GitHub** shrugged off the responsibility of the potential vulnerability, it becomes critical for organizations to take proactive steps to mitigate the risks.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F) [ ](https://twitter.com/intent/tweet?text=Vulnerable%20npm%20API%20exposes%20Private%20Packages%2C%20Why%20You%20Need%20to%20be%20Aware%20of%20it!&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fvulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it%2F) Copy 

Related Articles

- [ ![Spam Filters](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-9932.jpg)  10 Crucial Tips that Will Help You Avoid Spam Filters and Send Better Emails Email Security ](/blog/email-security/10-crucial-tips-that-will-help-you-avoid-spam-filters-and-send-better-emails/)
- [ ![Prevent Fraud](https://media.mailhop.org/duocircle/images/2022/07/hosted-email-server-8646.jpg)  7 Best Ways to Prevent Fraud Before It’s Too Late Email Security ](/blog/email-security/7-best-ways-to-prevent-fraud-before-its-too-late/)
- [ ![Email Security](https://media.mailhop.org/duocircle/images/2023/02/spf-record-4041.jpg)  7 Email Security Risks Facing Small Business Owners and How to Defend Against Them Email Security ](/blog/email-security/7-email-security-risks-facing-small-business-owners-and-how-to-defend-against-them/)
- [  7 Tips to Reinforce Your Business Email Security Email Security ](/blog/email-security/7-tips-to-reinforce-your-business-email-security/)

## Related Articles

[  Email Security 7m  10 Crucial Tips that Will Help You Avoid Spam Filters and Send Better Emails  Feb 14, 2023 ](/blog/email-security/10-crucial-tips-that-will-help-you-avoid-spam-filters-and-send-better-emails/)[  Email Security 9m  7 Best Ways to Prevent Fraud Before It’s Too Late  Jul 28, 2022 ](/blog/email-security/7-best-ways-to-prevent-fraud-before-its-too-late/)[  Email Security 10m  7 Email Security Risks Facing Small Business Owners and How to Defend Against Them  Feb 7, 2023 ](/blog/email-security/7-email-security-risks-facing-small-business-owners-and-how-to-defend-against-them/)[  Email Security 9m  7 Tips to Reinforce Your Business Email Security  Nov 9, 2022 ](/blog/email-security/7-tips-to-reinforce-your-business-email-security/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Vulnerable npm API exposes Private Packages, Why You Need to be Aware of it!","description":"The past few years saw a rise in the variety and volume of software supply chain attacks.","url":"https://www.duocircle.com/blog/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/","datePublished":"2022-10-24T18:56:21.000Z","dateModified":"2025-05-05T11:51:56.000Z","dateCreated":"2022-10-24T18:56:21.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/"},"articleSection":"email-security","keywords":"News, Security, Updates","wordCount":1169,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/10/SPF-record-checker-3896.jpg","caption":"Vulnerable npm API","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Security"},{"@type":"ListItem","position":3,"name":"Vulnerable npm API exposes Private Packages, Why You Need to be Aware of it!","item":"https://www.duocircle.com/blog/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Security","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Vulnerable npm API exposes Private Packages, Why You Need to be Aware of it!","item":"https://www.duocircle.com/blog/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Vulnerable npm API exposes Private Packages, Why You Need to be Aware of it!","description":"The past few years saw a rise in the variety and volume of software supply chain attacks.","url":"https://www.duocircle.com/blog/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/","datePublished":"2022-10-24T18:56:21.000Z","dateModified":"2025-05-05T11:51:56.000Z","dateCreated":"2022-10-24T18:56:21.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/"},"articleSection":"email-security","keywords":"News, Security, Updates","wordCount":1169,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/10/SPF-record-checker-3896.jpg","caption":"Vulnerable npm API","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
