Hackers launched the largest NPM crypto attack in history and compromised 18 JavaScript packages with billions of downloads. However, they stole less than $50. The largest NPM crypto attack in history has been confirmed this week. However, despite how large it was, its outcome was surprisingly small.  Despite affecting widely used JavaScript libraries downloaded billions […] The post Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50 appeared first on Live Bitcoin News.Hackers launched the largest NPM crypto attack in history and compromised 18 JavaScript packages with billions of downloads. However, they stole less than $50. The largest NPM crypto attack in history has been confirmed this week. However, despite how large it was, its outcome was surprisingly small.  Despite affecting widely used JavaScript libraries downloaded billions […] The post Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50 appeared first on Live Bitcoin News.

Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50

2025/09/10 06:43
3 min read

Hackers launched the largest NPM crypto attack in history and compromised 18 JavaScript packages with billions of downloads. However, they stole less than $50.

The largest NPM crypto attack in history has been confirmed this week. However, despite how large it was, its outcome was surprisingly small. 

Despite affecting widely used JavaScript libraries downloaded billions of times, hackers were able to steal less than $50 worth of crypto.

How Hackers Pulled Off the NPM Crypto Attack

Hackers gained access to the Node Package Manager (NPM) account of a well-known developer, Josh Junon, also known as “qix.” They used a phishing email that impersonated an official npmjs.com support address. The email urged Junon and other maintainers to update their two-factor authentication and threatened to lock accounts if they failed to comply.

Once Junon’s account was compromised, attackers injected malware into 18 of his NPM packages. These included widely used libraries like chalk, strip-ansi, and debug, which, when combined, see more than 2.6 billion downloads every week.

The malware worked as a crypto-clipper. 

It simply monitored Ethereum, Bitcoin, Solana, Tron, Litecoin and Bitcoin Cash wallet addresses. When a transaction was initiated, it simply replaced the destination address with an attacker-controlled address.

Damage Limited to Less Than $50

According to blockchain security firm Security Alliance, the financial effect was minimal. The hacker(s)’ Ethereum address, identified as “0xFc4a48”, has received less than $50 in assets. 

Initial reports showed only five cents stolen in Ether. Later, around $20 worth of a memecoin was added.

The wallet also received small amounts of tokens like Brett, Andy, Dork Lord, Ethervista and Gondola. This indicates that the attacker either failed to spread the malware widely enough or users quickly identified and blocked any suspicious transactions.

Why the NPM Crypto Attack Matters

Even though losses were small, the event further pointed out the risks of supply chain attacks. 

Developers who never directly installed the compromised packages may still have been exposed, because the libraries sit deep in dependency trees used by countless projects.

Ledger’s chief technology officer, Charles Guillemet, urged developers to be cautious and urged everyone to double-check wallet addresses during transactions. Crypto apps like Phantom Wallet and Uniswap also confirmed that they were not affected, while Ledger and MetaMask reassured users of their defenses.

DefiLlama founder 0xngmi noted that only projects updated after the hacker’s exploit was released could be at risk.

How the Malware Worked

According to Aikido Security, the injected code hooked into JavaScript functions like fetch, XMLHttpRequest, and wallet APIs like window Ethereum and Solana connectors. 

It intercepted crypto activity in the browser and manipulated wallet interactions, while rewriting the payment destinations.

This made the attack dangerous because it worked across multiple layers. It changed content displayed to users and tampered with API calls.

Still, the malware only affected users who installed the updated packages during the brief compromise window. This limited its reach compared to other large-scale hacks.

Lessons From the Largest NPM Crypto Attack

The incident further calls for the need for stronger security practices among developers. Two-factor authentication is important, but phishing emails that impersonate trusted services will always be effective. 

For crypto users, the advice is simple. Always verify wallet addresses before sending funds. Use wallets with built-in security layers like MetaMask and Ledger, which can block known malicious scripts.

Security firms also recommend that developers pin dependency versions in their projects and use automated scanning tools to detect any unexpected changes in libraries.

 

Market Opportunity
SecondLive Logo
SecondLive Price(LIVE)
$0.00003502
$0.00003502$0.00003502
-14.37%
USD
SecondLive (LIVE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Kraken's Big Hint: Pi Coin Set for Exchange Listing In 2026

Kraken's Big Hint: Pi Coin Set for Exchange Listing In 2026

Pi Coin (PI) is deeply embarked in the ongoing red light therapy that’s crunched the global crypto’s market capitalization below $2.4 trillion. The mobile mining
Share
Coinstats2026/02/07 09:25
US Stock Market Could Double By End Of Presidential Term

US Stock Market Could Double By End Of Presidential Term

The post US Stock Market Could Double By End Of Presidential Term appeared on BitcoinEthereumNews.com. Trump’s Bold Prediction: US Stock Market Could Double By
Share
BitcoinEthereumNews2026/02/07 10:43
Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales offload 200 million XRP leaving market uncertainty behind. XRP faces potential collapse as whales drive major price shifts. Is XRP’s future in danger after massive sell-off by whales? XRP’s price has been under intense pressure recently as whales reportedly offloaded a staggering 200 million XRP over the past two weeks. This massive sell-off has raised alarms across the cryptocurrency community, as many wonder if the market is on the brink of collapse or just undergoing a temporary correction. According to crypto analyst Ali (@ali_charts), this surge in whale activity correlates directly with the price fluctuations seen in the past few weeks. XRP experienced a sharp spike in late July and early August, but the price quickly reversed as whales began to sell their holdings in large quantities. The increased volume during this period highlights the intensity of the sell-off, leaving many traders to question the future of XRP’s value. Whales have offloaded around 200 million $XRP in the last two weeks! pic.twitter.com/MiSQPpDwZM — Ali (@ali_charts) September 17, 2025 Also Read: Shiba Inu’s Price Is at a Tipping Point: Will It Break or Crash Soon? Can XRP Recover or Is a Bigger Decline Ahead? As the market absorbs the effects of the whale offload, technical indicators suggest that XRP may be facing a period of consolidation. The Relative Strength Index (RSI), currently sitting at 53.05, signals a neutral market stance, indicating that XRP could move in either direction. This leaves traders uncertain whether the XRP will break above its current resistance levels or continue to fall as more whales sell off their holdings. Source: Tradingview Additionally, the Bollinger Bands, suggest that XRP is nearing the upper limits of its range. This often points to a potential slowdown or pullback in price, further raising concerns about the future direction of the XRP. With the price currently around $3.02, many are questioning whether XRP can regain its footing or if it will continue to decline. The Aftermath of Whale Activity: Is XRP’s Future in Danger? Despite the large sell-off, XRP is not yet showing signs of total collapse. However, the market remains fragile, and the price is likely to remain volatile in the coming days. With whales continuing to influence price movements, many investors are watching closely to see if this trend will reverse or intensify. The coming weeks will be critical for determining whether XRP can stabilize or face further declines. The combination of whale offloading and technical indicators suggest that XRP’s price is at a crossroads. Traders and investors alike are waiting for clear signals to determine if the XRP will bounce back or continue its downward trajectory. Also Read: Metaplanet’s Bold Move: $15M U.S. Subsidiary to Supercharge Bitcoin Strategy The post Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse? appeared first on 36Crypto.
Share
Coinstats2025/09/17 23:42