Skip to content

Build1 publisher3 min readPublished

1,400 npm maintainer domains, 18 flags, and one word doing too much work

A dev.to post scanned the domains behind the top 5,000 npm packages and found 18 with registration or email-security anomalies. The aggregate numbers matter more than the 18, and the headline overstates both.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying 1,400 npm maintainer domains, 18 flags, and one word doing too much work
Generated illustration

What happened

  • A developer publishing as onizuka on dev.to says that on the morning of July 28, 2024, they fed 1,400 domains into the Domain WHOIS API on RapidAPI, each one a homepage, documentation domain, or redirect extracted from the top 5,000 npm packages.
  • Eighteen of the 1,400 domains came back with registration or email-security anomalies, which the author frames as supply-chain warning signs rather than DNS trivia.
  • The post's headline is "I Ran 1,400 WHOIS Lookups. 18 Domains Were Compromised."
  • From the live run, 312 of the 1,400 domains had an email-security score below 50.
  • From the live run, 847 of the 1,400 domains had no DMARC enforcement at all.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

A developer publishing as onizuka on dev.to says that on the morning of July 28, 2024, they fed 1,400 domains into a RapidAPI WHOIS service, each one a homepage, documentation domain, or redirect extracted from the top 5,000 npm packages, and 18 came back with registration or email-security anomalies [1][2]. The 18 are the least useful number in the post. The aggregates are the ones worth acting on: according to the post, 312 of the 1,400 scored below 50 on the API's 0-100 email-security scale, 847 had no DMARC enforcement at all, and 94 were inside 90 days of expiry [4][5][6].

Read as proportions, that is 60.5 percent of the maintainer-facing domain surface with no DMARC enforcement [11], 22.3 percent below the midpoint on email posture [12], and 6.7 percent expiring within a quarter [13]. The flagged set is 1.3 percent [14]. The tail is small; the baseline is bad.

The author says they scored each record against five signals: domain age and expiration horizon, last WHOIS update date, DNSSEC status, email-security posture across SPF, DMARC, DKIM, DNSSEC and MTA-STS, and subdomain takeover risk graded HIGH, MEDIUM or LOW from certificate transparency logs and dangling records [15]. The 18 are said to break down as 9 with DMARC set to none or missing, 6 within 30 days of expiration with no auto-renew lock visible in RDAP, 4 with name-server changes in the previous 45 days, 3 with DNSSEC unsigned and SPF missing at once, and 2 rated HIGH for takeover because of dangling CNAMEs pointed at decommissioned cloud endpoints [8].

Then the problems. The headline is "I Ran 1,400 WHOIS Lookups. 18 Domains Were Compromised" [c2b], but nothing in the post describes a compromise; every finding is a hygiene or registration anomaly [22]. The post's own summary paragraph says three domains were within 30 days of expiration and six had no DMARC, which contradicts the later breakdown of six and nine [9][10]. And the only WHOIS record published is a cached example.com response, because the author says the API was asleep when they re-ran the query for the article [16][17]. No record from any flagged domain appears, and none of the 18 is named, which the author attributes to ongoing responsible disclosure [18]. A reader cannot check the finding.

The framing is still sound, and it is the part that survives the sourcing problems. The post pairs the scan with Aikido's write-up on the Shai-Hulud npm supply-chain attack, in which keyv, keyv-file, keyv-s3 and related packages were compromised through maintainer accounts and publishing infrastructure rather than a zero-day [19]. Trust in that model is inherited from things that look official because they are old, and an expiring domain is a transfer of that trust to whoever renews it. The author's own line is the sharpest thing in the piece: a package whose homepage expires in 60 days is a package whose homepage can be bought [21].

What to watch is whether anyone reproduces the aggregate. It is cheap work: the API takes up to 50 domains per request, so 1,400 is 28 calls [20][23]. Expiry horizon and DMARC state are the two signals with unambiguous failure modes and no interpretation required, which makes them the ones to put in your own dependency review before you take the 0-100 score seriously.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories