ABCDEFGH
1
NPM Supply Chain Security
2
WIP. Feel free to try password reset processes just far enough to take note of them (but don't actually do resets, that is illegal). Comment with what you find! Scripts to help automate this are very welcome.
3
If you like this kind of research and want to get to know us, chat with us on #!:matrix.org or irc.hashbang.sh/#! - Let's shine a spotlight on weak links in open source software security to protect everyone.
4
If your company relys on packages authored by one of these people, perhaps email them and offer to buy them a hardware 2FA device like a Yubikey, and disable insecure backup recovery methods
5
More importantly, it is worth understanding that NPM itself does not have any phishing resistant 2FA methods (like U2F) or signed package support. They have rejected these ideas, but let's prove to them why they need it.
6
UsernameE-mail
# Maintained
# Downstream
2FA Method (Least Secure)NotesContacted
7
mathiasmathias@qiwi.be60639856SMShad a yubikey option, but also had SMS recovery option
8
tjholowaychuktj@vision-media.ca54351276e-mail
9
jdaltonjohn.david.dalton@gmail.com48038447SMS, Reset Questions,, Backup E-mailContacted via twitter 1/11x
10
mikealmikeal.rogers@gmail.com20637363SMS, Reset Question, backup e-mailContacted via twitter 1/11x
11
somekittensrkoutnik@gmail.com2310787SMS, Recovery Question, backup e-mailaol backup e-mail
12
nylenjnylen@gmail.com4119504SMS, Reset Question, backup e-mail
13
shadowspawnnpm_j@ruru.gen.nz510790e-mail
14
fredkschottfkschott@gmail.com7218194SMSComcast recovery e-mail
15
simovsimeonvelichkov@gmail.com7519555SMS, Reset Question, backup e-mailContacted via e-mail 1/11x
16
abetomoabe@enzou.tokyo1110786
17
1000chshogosensui@gmail.com132803SMS, backup e-mailhotmail account
18
11bitburyak.ivan@yandex.ru1934
19
3rdedennpm@3rd-Eden.com8639
20
aaronaaron.heckmann+github@gmail.com3464
21
aaronabramovaaron@abramov.io2609
22
abernixnpmjs@jro.cc18
23
aboutblanknjuzhaoguoyan@foxmail.com0
24
acdliteacdlite@me.com19271
25
acdlitenpm@andrewclark.io19271
26
adam_baldwinevilpacket@gmail.com9619
27
adamvradam.rudd@uqconnect.edu.au297
28
addyosmaniaddyosmani@gmail.com13220
29
adrianheinemail@adrianheine.de800
30
aearlyalexander.early@gmail.com16994
31
afc163afc163@gmail.com1129
32
ahdinosaurmichael.williams@enspiral.com18344
33
aheckmannaaron.heckmann+github@gmail.com1683
34
ahmadnassriahmad@ahmadnassri.com8000
35
aiandrey@sitnik.ru7614
36
aikovendan.lytkin@gmail.com567
37
airbnbengopensource@airbnb.com6976
38
airbnbjordan.harband+npm@airbnb.com
39
ajedi32andrewm.bpi@gmail.com334
40
akirankiran@neostack.com1662
41
akryumguillaume.b.chau@gmail.com65
42
aleclarsonalec.stanford.larson@gmail.com10
43
alex3165alexr.3165@gmail.com122
44
alexalteaalexandro@phi.nz616
45
alexgilbertalex@punkave.com124
46
alexgorbatchevalex.gorbatchev@gmail.com3685
47
alexindigoiam@alexindigo.com838
48
alexlamslalexlamsl@gmail.com14318
49
alexmesserdmzt08@gmail.com3
50
alubbenpm@lubbe.org101
51
am11adeelbm@outlook.com2740
52
amasadamjad.masad@gmail.com1317
53
amaviscachris.amavisca@gmail.com2088
54
amidknightjosh@8fold.pro2293
55
amitoshamitosh.swain@gmail.com510
56
ampedandwiredcharles.blaxland@gmail.com1443
57
amphroamphro@gmail.com0
58
amzn-ossosa-3p@amazon.com1812
59
analog-niconicolai.kamenzky@testrails.org1198
60
anandthakkervestibule@anandthakker.net18042
61
anatrajkovskaana.trajkovska2015@gmail.com616
62
andaristmateuszburzynski@gmail.com1229
63
andreiglingeanuandrei.glingeanu@gmail.com17
64
andrewnezandrewnez@gmail.com2794
65
andybitzartzbitz@gmail.com616
66
andyearnshawandyearnshaw+npm@gmail.com117
67
andykogmail@andykog.com127
68
angularcoreangular-core+npm@google.com4256
69
angular-devkithansl@google.com0
70
angulardevops+npm@angular.io4292
71
annekimseyanne@npmjs.com0
72
anthonyshortantshort@gmail.com2556
73
antonkovalyovanton@kovalyov.net14176
74
anycli-botjdxcode+anycli@gmail.com0
75
aomarksaomarks@google.com181
76
apollo-botnpm@apollographql.com70
77
arbarbretz@gmail.com71
78
ariaminaeiaria.minaei@gmail.com160
79
aromanoaromano@preemptsecurity.com1154
80
arschmitzarschmitz@gmail.com162
81
arthurschreiberschreiber.arthur@googlemail.com268
82
arthurvrcontact@arthurverschaeve.be1972
83
artokunart.longbottom.jr@gmail.com50
84
arturarturadib@gmail.com3127
85
arunodaarunoda.susiripala@gmail.com831
86
arzafranfranco@basement.studio631
87
aseemkaseem.kishore@gmail.com1439
88
ashaffer88darawk@gmail.com17710
89
asiandrummerasiandrummer@gmail.com303
90
aslushnikovaslushnikov@gmail.com0
91
atcastleatcastle@gmail.com616
92
austinstarinaustin@punkave.com120
93
avianflucharlie@charlieistheman.com1061
94
awatermaawaterma@awaterma.net183
95
awearyKierkegaurd@gmail.com100
96
aws-sdk-botaws-sdk-js@amazon.com1809
97
axicalex@rtfs.hu197
98
ayoungandrewdyoung@gmail.com338
99
az7arulaz7arul@gmail.com607
100
azakusdfreedm2@gmail.com390