The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the… The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the…

NPM Hack Shows Supply Chain Threats Still Endanger Crypto

A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets.

Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.  

If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector. 

Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added. 

Largest NPM attack stole only $50 in crypto 

The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain. 

Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more. 

The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin. 

Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack

TON CTO breaks down NPM attack

Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published. 

Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions.

This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the users. 

He said that developers who pushed their builds within hours of the malicious updates and apps that auto-update their code libraries instead of freezing them to a safe version were the most exposed. 

Makosov shared a checklist on how developers can check if their apps were compromised. The main sign is whether the code is using one of 18 versions of popular libraries like ansi-styles, chalk or debug. He said if a project relies on these versions, it’s likely compromised. 

He said the fix is to switch back to safe versions, reinstall clean code and rebuild applications. He added that new and updated releases are already available and urged developers to act quickly to clear out the malware before it can affect their users. 

Magazine: BTS Jungkook’s hacker, Ripple backs Singapore payments firm: Asia Express

Source: https://cointelegraph.com/news/failed-npm-exploit-crypto-security-threat?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
Threshold Logo
Threshold Price(T)
$0,006497
$0,006497$0,006497
-%5,04
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
Q4 2024 Growth Beats Expectations With 0.9% Surge

Q4 2024 Growth Beats Expectations With 0.9% Surge

The post Q4 2024 Growth Beats Expectations With 0.9% Surge appeared on BitcoinEthereumNews.com. New Zealand Retail Sales Soar: Q4 2024 Growth Beats Expectations
Share
BitcoinEthereumNews2026/02/23 07:03
Vitalik Buterin Explains How Crypto Can Protect Users When Perfect Security Remains Impossible

Vitalik Buterin Explains How Crypto Can Protect Users When Perfect Security Remains Impossible

Ethereum co-founder Vitalik Buterin has outlined a new framework for crypto security, offering practical strategies rooted in redundancy, multi-angle verification
Share
Coinstats2026/02/23 06:08