Hackers launched the largest NPM crypto attack in history and compromised 18 JavaScript packages with billions of downloads. However, they stole less than $50. The largest NPM crypto attack in history has been confirmed this week. However, despite how large it was, its outcome was surprisingly small.  Despite affecting widely used JavaScript libraries downloaded billions […] The post Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50 appeared first on Live Bitcoin News.Hackers launched the largest NPM crypto attack in history and compromised 18 JavaScript packages with billions of downloads. However, they stole less than $50. The largest NPM crypto attack in history has been confirmed this week. However, despite how large it was, its outcome was surprisingly small.  Despite affecting widely used JavaScript libraries downloaded billions […] The post Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50 appeared first on Live Bitcoin News.

Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50

Hackers launched the largest NPM crypto attack in history and compromised 18 JavaScript packages with billions of downloads. However, they stole less than $50.

The largest NPM crypto attack in history has been confirmed this week. However, despite how large it was, its outcome was surprisingly small. 

Despite affecting widely used JavaScript libraries downloaded billions of times, hackers were able to steal less than $50 worth of crypto.

How Hackers Pulled Off the NPM Crypto Attack

Hackers gained access to the Node Package Manager (NPM) account of a well-known developer, Josh Junon, also known as “qix.” They used a phishing email that impersonated an official npmjs.com support address. The email urged Junon and other maintainers to update their two-factor authentication and threatened to lock accounts if they failed to comply.

Once Junon’s account was compromised, attackers injected malware into 18 of his NPM packages. These included widely used libraries like chalk, strip-ansi, and debug, which, when combined, see more than 2.6 billion downloads every week.

The malware worked as a crypto-clipper. 

It simply monitored Ethereum, Bitcoin, Solana, Tron, Litecoin and Bitcoin Cash wallet addresses. When a transaction was initiated, it simply replaced the destination address with an attacker-controlled address.

Damage Limited to Less Than $50

According to blockchain security firm Security Alliance, the financial effect was minimal. The hacker(s)’ Ethereum address, identified as “0xFc4a48”, has received less than $50 in assets. 

Initial reports showed only five cents stolen in Ether. Later, around $20 worth of a memecoin was added.

The wallet also received small amounts of tokens like Brett, Andy, Dork Lord, Ethervista and Gondola. This indicates that the attacker either failed to spread the malware widely enough or users quickly identified and blocked any suspicious transactions.

Why the NPM Crypto Attack Matters

Even though losses were small, the event further pointed out the risks of supply chain attacks. 

Developers who never directly installed the compromised packages may still have been exposed, because the libraries sit deep in dependency trees used by countless projects.

Ledger’s chief technology officer, Charles Guillemet, urged developers to be cautious and urged everyone to double-check wallet addresses during transactions. Crypto apps like Phantom Wallet and Uniswap also confirmed that they were not affected, while Ledger and MetaMask reassured users of their defenses.

DefiLlama founder 0xngmi noted that only projects updated after the hacker’s exploit was released could be at risk.

How the Malware Worked

According to Aikido Security, the injected code hooked into JavaScript functions like fetch, XMLHttpRequest, and wallet APIs like window Ethereum and Solana connectors. 

It intercepted crypto activity in the browser and manipulated wallet interactions, while rewriting the payment destinations.

This made the attack dangerous because it worked across multiple layers. It changed content displayed to users and tampered with API calls.

Still, the malware only affected users who installed the updated packages during the brief compromise window. This limited its reach compared to other large-scale hacks.

Lessons From the Largest NPM Crypto Attack

The incident further calls for the need for stronger security practices among developers. Two-factor authentication is important, but phishing emails that impersonate trusted services will always be effective. 

For crypto users, the advice is simple. Always verify wallet addresses before sending funds. Use wallets with built-in security layers like MetaMask and Ledger, which can block known malicious scripts.

Security firms also recommend that developers pin dependency versions in their projects and use automated scanning tools to detect any unexpected changes in libraries.

 

Piyasa Fırsatı
SecondLive Logosu
SecondLive Fiyatı(LIVE)
$0.00005187
$0.00005187$0.00005187
+4.49%
USD
SecondLive (LIVE) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts?

Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts?

The post Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts? appeared on BitcoinEthereumNews.com. In recent crypto news, Stephen Miran swore in as the latest Federal Reserve governor on September 16, 2025, slipping into the board’s last open spot right before the Federal Open Market Committee kicks off its two-day rate discussion. Traders are betting heavily on a 25-basis-point trim, which would bring the federal funds rate down to 4.00%-4.25%, based on CME FedWatch Tool figures from September 15, 2025. Miran, who’s been Trump’s top economic advisor and a supporter of his trade ideas, joins a seven-member board where just three governors come from Democratic picks, according to the Fed’s records updated that same day. Crypto News: Miran’s Background and Quick Path to Confirmation The Senate greenlit Miran on September 15, 2025, with a tight 48-47 vote, following his nomination on September 2, 2025, as per a recent crypto news update. His stint runs only until January 31, 2026, stepping in for Adriana D. Kugler, who stepped down in August 2025 for reasons not made public. Miran earned his economics Ph.D. from Harvard and worked at the Treasury back in Trump’s first go-around. Afterward, he moved to Hudson Bay Capital Management as an economist, then looped back to the White House in December 2024 to head the Council of Economic Advisers. There, he helped craft Trump’s “reciprocal tariffs” approach, aimed at fixing trade gaps with China and the EU. He wouldn’t quit his White House gig, which irked Senator Elizabeth Warren at the September 7, 2025, confirmation hearings. That limited time frame means Miran gets to cast a vote straight away at the FOMC session starting September 16, 2025. The full board now features Chair Jerome H. Powell (Trump pick, term ends 2026), Vice Chair Philip N. Jefferson (Biden, to 2036), and folks like Lisa D. Cook (Biden, to 2028) and Michael S. Barr…
Paylaş
BitcoinEthereumNews2025/09/18 03:14
Kodiak Sciences Announces Pricing of Upsized Public Offering of Common Stock

Kodiak Sciences Announces Pricing of Upsized Public Offering of Common Stock

PALO ALTO, Calif., Dec. 16, 2025 /PRNewswire/ — Kodiak Sciences Inc. (Nasdaq: KOD), a precommercial retina focused biotechnology company committed to researching
Paylaş
AI Journal2025/12/17 12:15
Oil jumps over 1% on Venezuela oil blockade

Oil jumps over 1% on Venezuela oil blockade

Oil prices rose more than 1 percent on Wednesday after US President Donald Trump ordered “a total and complete” blockade of all sanctioned oil tankers entering
Paylaş
Agbi2025/12/17 11:55