VerifiVerifi Security
Products
Use cases
Resources
Pricing
Company
ResourcesGet Started
Back to blog
Case study

Case Study: The event-stream Incident

· 1 min read

before publishing.

In 2018, event-stream, a widely-used npm package with millions of weekly downloads, was weaponised in one of the clearest examples of maintainer takeover by social engineering.

What happened

Why it was hard to catch

What defenders learn

How Verifi analyses dependency behaviour →

Related
  • Maintainer & Account Takeover
  • Malicious Install Scripts
  • Known vs Novel Malware in Dependencies
More from the blog
Case study

Case Study: The Codecov Bash Uploader Compromise

Case study

Case Study: PyTorch / torchtriton Dependency Confusion

Get the latest on supply-chain threats

New malicious packages and IOCs, straight from the corpus. No spam.

Products
  • Overview
  • Verifi CLI
  • Verifi Firewall
  • Verifi Intel
  • Verifi CodeFix
  • Verifi Workflows
Use cases
  • Block malicious packages
  • Catch novel threats
  • Incident response
  • Cut alert noise
  • Prove compliance
Resources
  • All articles
  • Supply-chain 101
  • Glossary
  • FAQ
  • MITRE ATT&CK
Company
  • Why Verifi
  • Platform
  • Trust and security
  • Compliance
  • Pricing
  • Contact
VerifiVerifi Security© 2026. All rights reserved.
ProductsResearchContact
© 2026 Verifi Security.