This week on The Secure Disclosure, host Mackenzie Jackson dives into “the largest breach that never really happened” the September npm supply chain compromise that put 2.6 billion weekly downloads at risk but somehow didn’t take down the internet. Joining me are two key voices from the incident: Josh Junon – the maintainer who was phished, unknowingly triggering the chain of events. Charlie Erikson – the security researcher who first discovered and analyzed the malware. Together, we unpack the timeline: the phishing email that started it all, the malware hidden inside foundational packages like debug and chalk, the viral panic that followed, and why the attackers walked away with just $900 in crypto instead of world domination. We also discuss what the breach teaches us about security “working,” luck, and where the ecosystem still leaves maintainers dangerously exposed. Sponsor This episode is brought to you by Aikido Security — your complete code security platform. Check out Aikido: https://aikido.dev Prevent supplychain attacks with Aikido SafeChain: https://www.npmjs.com/package/@aikidosec/safe-chain Watch & Listen 🎧 Spotify & other platforms: https://creators.spotify.com/pod/profile/thesecuredisclosure/ Connect with Me X (Twitter): https://x.com/advocatemack LinkedIn: https://linkedin.com/in/adovcatemack References XKCD Web Comic: https://xkcd.com/2347/ Wiz Blog Post: https://www.wiz.io/blog/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debug-chalk InsiderPhD YouTube: https://www.youtube.com/c/InsiderPhD InsiderPhD X Post: https://x.com/InsiderPhD/status/1965110610972250550 My LinkedIn Post: https://www.linkedin.com/feed/update/urn:li:activity:7373625746822696960/ John Hammond Video: https://www.youtube.com/watch?v=4caJw0JJZTQ Chapters 00:00 – Intro 00:18 – Setting the stage: the breach that “never really happened” 01:31 – Josh Junon: the phishing email that started it all 04:39 – Malware injection and Charlie Erikson’s discover