← Timescale

2025 Timescale — malicious npm campaign targeting maintainers; Timescale acknowledged maintainer account impact

2025 Unknown records affected Share on X

Data compromised

Maintainer credentials and integrity of affected package namespaces during the campaign window.

Technical writeup

Industry reporting described a wave of malicious npm publications targeting OSS maintainers; maintainers including Timescale publicly confirmed account impact and remediation messaging in community threads summarized by outlets.

Root cause

Supply-chain attack on maintainer identities and publishing workflows (per summarized reporting).

References