2025 Timescale — malicious npm campaign targeting maintainers; Timescale acknowledged maintainer account impact
Data compromised
Maintainer credentials and integrity of affected package namespaces during the campaign window.
Technical writeup
Industry reporting described a wave of malicious npm publications targeting OSS maintainers; maintainers including Timescale publicly confirmed account impact and remediation messaging in community threads summarized by outlets.
Root cause
Supply-chain attack on maintainer identities and publishing workflows (per summarized reporting).