The PureScript npm Installer Sabotage
Updated 5 Oct 2026 · Incident date 5 Jul 2019 · npm
load-from-cwd-or-npm 3.0.1 -> 3.0.2 and rate-map 1.0.2 -> 1.0.3index.js in both packages: load-from-cwd-or-npm/index.j...Two npm packages, load-from-cwd-or-npm 3.0.2 and rate-map 1.0.3, sabotaged the PureScript npm installer in July 2019. They made the installer hang instead of finishing. The code did not steal data.
Both packages belonged to the same maintainer, who was a former author of the installer.
What happened
The PureScript installer is a package that downloads a prebuilt compiler. Its maintainers took over from the original author, Shinnosuke Watanabe (@shinnn), after a disagreement, according to The Register. The PureScript 0.13.2 release on 5 July 2019 was the first from the new team.
The PureScript maintainer's write-up gives this timeline in UTC:
- 5 July, about 21:00:
load-from-cwd-or-npm@3.0.2published - 9 July, about 01:00: a user, @doolse, identified the problem
- 9 July, about 05:00: clean
load-from-cwd-or-npm@3.0.4published - 9 July, about 08:00:
rate-map@1.0.3published - 9 July, about 11:30: the code in
rate-mapfound - 9 July, about 14:00: a fixed installer, 0.2.5, released
The first package returned a PassThrough stream instead of the expected package, so the installer hung at the step that checks for a prebuilt binary. The second package removed callback behavior and deleted itself to hide evidence. The code ran only when the PureScript installer used it, and not when the original author's own packages did.
Watanabe said an attacker gained access to his npm account. The Register notes that this is not settled.
Affected versions
load-from-cwd-or-npm3.0.2 (clean 3.0.4 followed)rate-map1.0.3- The PureScript npm installer before the fix, which depended on these packages
Both malicious versions were later removed from the registry. The write-up recommends upgrading to PureScript 0.13.2 or later, and says the maintainers removed or copied into their own code all dependencies by @shinnn. This is only partly detectable by comparing files. The 3.0.2 change gave the package no new capability, because it only returned a wrong value.
Indicators of compromise
load-from-cwd-or-npmversion 3.0.2 in a lockfile ornode_modulesrate-mapversion 1.0.3 in a lockfile ornode_modules- An install of
purescriptthat hangs at the message "Check if a prebuilt binary is provided for your platform"
How to check
List the two packages in your dependency tree.
npm ls load-from-cwd-or-npm rate-map
Search lockfiles for the bad versions.
grep -rnE "load-from-cwd-or-npm|rate-map" package-lock.json yarn.lock 2>/dev/null
What to do now
- Update
purescriptto 0.13.2 or later. - Remove or update
load-from-cwd-or-npmandrate-mapso that no bad version remains. - Reinstall dependencies from a clean lockfile.
- Treat package maintainer disputes as a risk signal. Pin versions and review dependency updates.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 64 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED index.js It now downloads from the internet. It did not before.
Frequently asked questions
What did the malicious PureScript npm packages do?
They sabotaged the PureScript installer so it hung during the prebuilt binary check. The sources do not describe data theft.
Which versions were malicious?
load-from-cwd-or-npm 3.0.2 and rate-map 1.0.3. Clean version 3.0.4 of load-from-cwd-or-npm followed on 9 July 2019.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.