The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the… The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the…

NPM Hack Shows Supply Chain Threats Still Endanger Crypto

2025/09/10 10:36
Okuma süresi: 3 dk

A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets.

Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.  

If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector. 

Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added. 

Largest NPM attack stole only $50 in crypto 

The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain. 

Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more. 

The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin. 

Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack

TON CTO breaks down NPM attack

Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published. 

Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions.

This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the users. 

He said that developers who pushed their builds within hours of the malicious updates and apps that auto-update their code libraries instead of freezing them to a safe version were the most exposed. 

Makosov shared a checklist on how developers can check if their apps were compromised. The main sign is whether the code is using one of 18 versions of popular libraries like ansi-styles, chalk or debug. He said if a project relies on these versions, it’s likely compromised. 

He said the fix is to switch back to safe versions, reinstall clean code and rebuild applications. He added that new and updated releases are already available and urged developers to act quickly to clear out the malware before it can affect their users. 

Magazine: BTS Jungkook’s hacker, Ripple backs Singapore payments firm: Asia Express

Source: https://cointelegraph.com/news/failed-npm-exploit-crypto-security-threat?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Piyasa Fırsatı
Threshold Logosu
Threshold Fiyatı(T)
$0.006539
$0.006539$0.006539
-4.42%
USD
Threshold (T) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Bitcoin’s Alarming Slide: On Track for Fifth Straight Month of Losses, Nears Historic Losing Streak

Bitcoin’s Alarming Slide: On Track for Fifth Straight Month of Losses, Nears Historic Losing Streak

BitcoinWorld Bitcoin’s Alarming Slide: On Track for Fifth Straight Month of Losses, Nears Historic Losing Streak Global cryptocurrency markets are witnessing a
Paylaş
bitcoinworld2026/02/23 10:40
Bitcoin Bulls Need to Reclaim This Key Level for a New Run at $125K

Bitcoin Bulls Need to Reclaim This Key Level for a New Run at $125K

The post Bitcoin Bulls Need to Reclaim This Key Level for a New Run at $125K appeared on BitcoinEthereumNews.com. Key points: Bitcoin bulls are busy flipping key levels back to support; can they crack $118,000 next? New all-time highs are on the horizon if the Fed reaction uptrend continues. Exchange traders are already bringing in large lines of liquidity on either side of price. Bitcoin (BTC) sought to flip $117,000 to support on Thursday as the Federal Reserve interest-rate cut boosted crypto markets. BTC/USD one-hour chart. Source: Cointelegraph/TradingView Watch these Bitcoin price levels next, say traders Data from Cointelegraph Markets Pro and TradingView showed BTC/USD gaining up to 1.3% after the daily close. Volatility hit as the US Federal Reserve announced its first rate cut of 2025, coming in at 0.25% to match market expectations. After a brief dip below $115,000, Bitcoin rebounded, liquidating both long and short positions to the tune of over $100 million over 24 hours. $BTC update: FOMC Price Action nailed 🔨 Boring Monday and Tuesday; Wednesday volatile with the classic retrace of an initial false move. $105M liquidated in 30mins during FOMC, that’s what it’s important to be aware of this. Absolutely love this market. Probably $120k next. https://t.co/azE7Fg6J10 pic.twitter.com/x3EPCmIlOx — CrypNuevo 🔨 (@CrypNuevo) September 17, 2025 Among traders, hopes were high that bulls would cement support and continue on to challenge all-time highs. “The more important part; will $BTC break through this crucial resistance zone?” crypto trader, analyst and entrepreneur Michaël van de Poppe queried in a post on X. An accompanying chart showed the bulls’ next battle at $118,000.  “All I’m sure about is that, once Bitcoin stabilizes, we’ll start to see big breakouts on Altcoins occur,” he added. BTC/USDT one-day chart with RSI, volume data. Source: Michaël van de Poppe/X Popular trader Daan Crypto Trades agreed on the significance of the $118,000 mark. During dovish comments by Fed Chair Jerome Powell…
Paylaş
BitcoinEthereumNews2025/09/19 10:20
Vitalik proposed introducing transaction demo functionality to improve Ethereum's security.

Vitalik proposed introducing transaction demo functionality to improve Ethereum's security.

PANews reported on February 23 that Ethereum co-founder Vitalik Buterin recently suggested on the X platform that features such as "transaction simulation" be used
Paylaş
PANews2026/02/23 09:54