Chinese PRC shenanigans in the npm mirror ecosystem @OWASPGLOBAL
Chinese PRC shenanigans in the npm mirror ecosystem  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/b2/PRC%20Shenanigans%20-%20OWASP%20Global%20AppSec%202025.pptx

npm is the world's largest and most popular software registry. Unfortunately, attackers target npm packages because they know existing security tools like SCA or EDR don't protect developers from malicious npm packages

When a researcher or the GitHub security team identifies a malicious package, npm removes it from the registry to prevent further downloads. All servers in the npm mirror ecosystem are then supposed to remove the malicious package from their local copies of the npm database.

Of the 8 global npm mirrors worldwide, five are located in China, representing 63% of all npm mirrors. During my in-depth research of the npm ecosystem, particularly the Chinese npm mirrors, I discovered something concerning: while Chinese npm mirrors appear to remove malware from their registries, they continue to serve it, albeit hidden. Why is it that only Chinese npm servers do this?!

I’ve been using this bug for two years to get access to malware that almost no one else has seen. In this presentation, I will show exactly how I do this with the audience so they can enjoy the same supply of tasty, npm malware!

Paul McCarty
Safety
Head of Research at Safety. Founder of SecureStack, GitHax and SourceCodeRED. Software supply chain offensive security crazy person.
Gold Coast, Queensland

twitter.com/eastsidemccarty
linkedin.com/in/mccartypaul

Paul is the Head of Research at Safety (safetycli.com) and a well-known researcher in the malicious packages space, as well as being a DevSecOps OG. He founded multiple startups including SecureStack in 2017, SourceCodeRED in 2023 and GitHax in 2024 . Paul has worked for NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, and Australian government amongst others. Paul is a frequent contributor to open source and is the author of several DevSecOps, software supply chain and threat modelling projects. He’s currently writing a book entitled “Hacking NPM” and when he’s not doing that he’s snowboarding with his wife and 3 amazing kids.

@eastsidemccarty
linkedin.com/in/mccartypaul
safetycli.com (company)
sourcecodered.com/blog (blog)

Managed by the OWASP® Foundation
owasp.org
Chinese PRC shenanigans in the npm mirror ecosystemSecurity Exception Management: Balancing Risk with Reality at Enterprise ScaleThe Past, Present, and Future of Automated RemediationInstall Once, Exploit Forever: The MCP Plugin Supply Chain Attack Surface - Track 1Web Security Experts: Are you overlooking WebRTC vulnerabilities? - Sandro GauciOWASP AppSec Day France HighlightOWASP Board of Directors - February 2026I Know What You Did Last Summer: Lessons Learned from Privacy Breaches and Scandals - Dr. Kim WuytsAI Under the Hood: Unmasking Hidden Threats - Dr. Nitish M. UplavikarOWASP Nettacker - Arkadii Yakovets, Sam StepanyanMillions Of Public Certificates Are Reusing Old Private Keys - Dylan Ayrey, Joseph LeonIt’s Giving Insecure Vibes: Secure Coding Literacy for Vibe Coders Track 1
OWASP Foundation |

Chinese PRC shenanigans in the npm mirror ecosystem

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER