No Result
View All Result
  • Login
Tuesday, December 16, 2025
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Cryptocurrency

Lessons From NPM Crypto Exploit Near-Miss

by FeeOnlyNews.com
3 months ago
in Cryptocurrency
Reading Time: 10 mins read
A A
0
Lessons From NPM Crypto Exploit Near-Miss
Share on FacebookShare on TwitterShare on LInkedIn


A failed attack on popular Node Package Manager (NPM)
libraries sent shockwaves through the crypto world on Monday.

Hackers targeted major packages to hijack
cryptocurrency transactions across multiple blockchains, but due to coding
errors, the breach caused minimal loss.

Still, experts warn that the incident highlights ongoing
risks for software wallets, exchanges, and any platform that automatically
updates code libraries.

NPM Attack Hits Popular Libraries

The attack reportedly started with a phishing email
sent from a fake NPM support domain, which allowed hackers to access developer accounts. Malicious updates were then pushed to libraries, including chalk, debug, and strip-ansi.

The injected code attempted to intercept wallet
addresses on chains like Bitcoin, Ethereum
Ethereum

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,
Read this Term
, Solana, Tron, and Litecoin.

Charles Guillemet, Ledger’s CTO, commented on X: “The
attack fortunately failed, with almost no victims. It began with a phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term

email from a fake npm support domain that stole credentials and gave attackers
access to publish malicious package updates.”

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,… https://t.co/Ud1SBSJ52v pic.twitter.com/lOik6k7Dkp

— Charles Guillemet (@P3b7_) September 9, 2025

According to Guillemet, the injected code targeted web
crypto activity, affecting Ethereum, Solana, and other blockchains, hijacking
transactions and replacing wallet addresses directly in network responses.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

“If your funds sit in a software wallet or on an
exchange, you’re one code execution away from losing everything. Supply-chain
compromises remain a powerful malware delivery vector, and we’re also seeing
more targeted attacks emerge,” he said.

Understanding the Threat

Anatoly Makosov, CTO of The Open Network (TON), also addressed the matter by explaining the mechanics of the attack on X and that only 18 specific package versions were compromised.

Makosov said developers who deployed builds shortly
after the malicious updates, or who rely on auto-updating libraries, were most
exposed. “Developers of multi-chain products should check their code,
especially if they have released something today,” he warned.

⚠️ Attack on popular NPM packages — technical details

A few hours ago, hackers gained access to some NPM accounts and published infected versions of popular libraries.

Many web products use these packages.

Although TON products do not appear to be at risk, developers of…

— Anatoly Makosov (@anatoly_makosov) September 8, 2025

Makosov emphasized that all earlier and newer versions
of the allegedly attacked packages are considered safe. Fixes have been
published, and developers are urged to reinstall clean code and rebuild their
applications.

Minimal Impact, Major Lesson

Despite the sophisticated attempt, the financial
impact was limited. Guillemet credited early detection to errors in the
attackers’ code that caused CI/CD pipeline crashes.

“Hardware wallets are built to withstand these
threats,” Guillemet said. Ledger devices include Clear Signing, letting users
verify transactions on a secure screen, and Transaction Check, which warns of
suspicious activity. “Your private keys and recovery phrase remain safe.
The immediate danger may have passed, but the threat hasn’t. Stay safe,” he
added.

Makosov and Guillemet both emphasized that vigilance
is crucial. Developers should lock dependencies to safe versions and avoid
dynamic updates, while users should avoid blind signing and always verify
wallet addresses.

Meanwhile, crypto wallet provider Ledger has assured
its users that its systems remain safe.

Ledger devices are not and have not been at risk during an ecosystem-wide software supply chain attack that was discovered.

Ledger devices are built specifically to protect users against attacks like these.

Only Ledger devices have secure screens, powered by the Secure Element… https://t.co/cJO2w0dpmU

— Ledger (@Ledger) September 8, 2025

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these,” the company mentioned.

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these.”

Developers have now been urged to examine their
projects’ package files for affected versions and update or rebuild with secure
releases. Users, meanwhile, should avoid blind signing and always verify wallet
addresses before confirming transactions.

A failed attack on popular Node Package Manager (NPM)
libraries sent shockwaves through the crypto world on Monday.

Hackers targeted major packages to hijack
cryptocurrency transactions across multiple blockchains, but due to coding
errors, the breach caused minimal loss.

Still, experts warn that the incident highlights ongoing
risks for software wallets, exchanges, and any platform that automatically
updates code libraries.

NPM Attack Hits Popular Libraries

The attack reportedly started with a phishing email
sent from a fake NPM support domain, which allowed hackers to access developer accounts. Malicious updates were then pushed to libraries, including chalk, debug, and strip-ansi.

The injected code attempted to intercept wallet
addresses on chains like Bitcoin, Ethereum
Ethereum

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,
Read this Term
, Solana, Tron, and Litecoin.

Charles Guillemet, Ledger’s CTO, commented on X: “The
attack fortunately failed, with almost no victims. It began with a phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term

email from a fake npm support domain that stole credentials and gave attackers
access to publish malicious package updates.”

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,… https://t.co/Ud1SBSJ52v pic.twitter.com/lOik6k7Dkp

— Charles Guillemet (@P3b7_) September 9, 2025

According to Guillemet, the injected code targeted web
crypto activity, affecting Ethereum, Solana, and other blockchains, hijacking
transactions and replacing wallet addresses directly in network responses.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

“If your funds sit in a software wallet or on an
exchange, you’re one code execution away from losing everything. Supply-chain
compromises remain a powerful malware delivery vector, and we’re also seeing
more targeted attacks emerge,” he said.

Understanding the Threat

Anatoly Makosov, CTO of The Open Network (TON), also addressed the matter by explaining the mechanics of the attack on X and that only 18 specific package versions were compromised.

Makosov said developers who deployed builds shortly
after the malicious updates, or who rely on auto-updating libraries, were most
exposed. “Developers of multi-chain products should check their code,
especially if they have released something today,” he warned.

⚠️ Attack on popular NPM packages — technical details

A few hours ago, hackers gained access to some NPM accounts and published infected versions of popular libraries.

Many web products use these packages.

Although TON products do not appear to be at risk, developers of…

— Anatoly Makosov (@anatoly_makosov) September 8, 2025

Makosov emphasized that all earlier and newer versions
of the allegedly attacked packages are considered safe. Fixes have been
published, and developers are urged to reinstall clean code and rebuild their
applications.

Minimal Impact, Major Lesson

Despite the sophisticated attempt, the financial
impact was limited. Guillemet credited early detection to errors in the
attackers’ code that caused CI/CD pipeline crashes.

“Hardware wallets are built to withstand these
threats,” Guillemet said. Ledger devices include Clear Signing, letting users
verify transactions on a secure screen, and Transaction Check, which warns of
suspicious activity. “Your private keys and recovery phrase remain safe.
The immediate danger may have passed, but the threat hasn’t. Stay safe,” he
added.

Makosov and Guillemet both emphasized that vigilance
is crucial. Developers should lock dependencies to safe versions and avoid
dynamic updates, while users should avoid blind signing and always verify
wallet addresses.

Meanwhile, crypto wallet provider Ledger has assured
its users that its systems remain safe.

Ledger devices are not and have not been at risk during an ecosystem-wide software supply chain attack that was discovered.

Ledger devices are built specifically to protect users against attacks like these.

Only Ledger devices have secure screens, powered by the Secure Element… https://t.co/cJO2w0dpmU

— Ledger (@Ledger) September 8, 2025

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these,” the company mentioned.

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these.”

Developers have now been urged to examine their
projects’ package files for affected versions and update or rebuild with secure
releases. Users, meanwhile, should avoid blind signing and always verify wallet
addresses before confirming transactions.





Source link

Tags: CryptoexploitLessonsnearmissNPM
ShareTweetShare
Previous Post

Amsterdam’s Nebius shares soar 51% after sealing €16.5B AI infrastructure deal with Microsoft

Next Post

Cassidy Raises $10M to Scale Context-Powered AI Automation for Non-Technical Teams – AlleyWatch

Related Posts

Solana Price Outlook After Charles Schwab Adds SOL Futures

Solana Price Outlook After Charles Schwab Adds SOL Futures

by FeeOnlyNews.com
December 16, 2025
0

Solana price remains in focus as institutional access expands through regulated derivatives products. The exposure to futures now puts Solana...

Solana’s seamless operation post-DDoS signals a new era

Solana’s seamless operation post-DDoS signals a new era

by FeeOnlyNews.com
December 16, 2025
0

Over the past years, the institutional knock against Solana was simple: the network broke under pressure.This week, the network quietly...

Dogecoin Price Squeeze Maps Out Two Possible Scenarios From Here

Dogecoin Price Squeeze Maps Out Two Possible Scenarios From Here

by FeeOnlyNews.com
December 16, 2025
0

Crypto analyst Erick Crypto has highlighted a Dogecoin price squeeze, which is currently playing out. Based on this, he mentioned...

The Winklevoss Twins Just Launched Gemini Predictions in the US

The Winklevoss Twins Just Launched Gemini Predictions in the US

by FeeOnlyNews.com
December 16, 2025
0

Gemini started offering prediction markets across the United States this week, capping a five-year effort to secure federal approval and...

Libra’s Launch Was Calculated: New Revelations Hint at Milei’s Involvement

Libra’s Launch Was Calculated: New Revelations Hint at Milei’s Involvement

by FeeOnlyNews.com
December 16, 2025
0

A local media article alleges that Mauricio Novelli and Manuel Terrones Godoy, two crypto entrepreneurs, were present when Libra was...

Bitcoin Outperforms Altcoins Despite Market-Wide Decline

Bitcoin Outperforms Altcoins Despite Market-Wide Decline

by FeeOnlyNews.com
December 16, 2025
0

Despite a decline from all-time highs, Bitcoin has still performed better than most other cryptocurrency sectors in recent months, indicating...

Next Post
Cassidy Raises M to Scale Context-Powered AI Automation for Non-Technical Teams – AlleyWatch

Cassidy Raises $10M to Scale Context-Powered AI Automation for Non-Technical Teams – AlleyWatch

Mortgage Rates Today, Tuesday, September 9: Noticeably Lower

Mortgage Rates Today, Tuesday, September 9: Noticeably Lower

  • Trending
  • Comments
  • Latest
Newsom, DeSantis join forces to blast ‘idiotic’ push to allow oil drilling off coasts of California, Florida

Newsom, DeSantis join forces to blast ‘idiotic’ push to allow oil drilling off coasts of California, Florida

November 23, 2025
Israeli housing rental platform Venn raises m

Israeli housing rental platform Venn raises $52m

November 18, 2025
What is a credit card spending limit — and what to know

What is a credit card spending limit — and what to know

August 4, 2025
Links 12/10/2025 | naked capitalism

Links 12/10/2025 | naked capitalism

December 10, 2025
5 Senior Discounts Being Eliminated by National Retailers

5 Senior Discounts Being Eliminated by National Retailers

December 7, 2025
AT&T promised the government it won’t pursue DEI

AT&T promised the government it won’t pursue DEI

December 4, 2025
Trump turns on CBS, Kushner pulls out and Paramount’s hostile bid for Warner Bros. shows signs of collapse

Trump turns on CBS, Kushner pulls out and Paramount’s hostile bid for Warner Bros. shows signs of collapse

0
Nasdaq moves to near 24-hour trading. Some say that’s a bad idea

Nasdaq moves to near 24-hour trading. Some say that’s a bad idea

0
The Growth Story Behind Insurance-Linked Securities

The Growth Story Behind Insurance-Linked Securities

0
20 Best Christmas Gift Ideas for Boys (Under !)

20 Best Christmas Gift Ideas for Boys (Under $30!)

0
Tom Livne, Eyal Waldman raising 0m for SPAC

Tom Livne, Eyal Waldman raising $200m for SPAC

0
Parallel Learning Raises M to Expand Virtual Special Education Services Nationwide – AlleyWatch

Parallel Learning Raises $20M to Expand Virtual Special Education Services Nationwide – AlleyWatch

0
Trump turns on CBS, Kushner pulls out and Paramount’s hostile bid for Warner Bros. shows signs of collapse

Trump turns on CBS, Kushner pulls out and Paramount’s hostile bid for Warner Bros. shows signs of collapse

December 16, 2025
20 Best Christmas Gift Ideas for Boys (Under !)

20 Best Christmas Gift Ideas for Boys (Under $30!)

December 16, 2025
EBRI: 401(k) loans serve as health and housing lifeline

EBRI: 401(k) loans serve as health and housing lifeline

December 16, 2025
Solana Price Outlook After Charles Schwab Adds SOL Futures

Solana Price Outlook After Charles Schwab Adds SOL Futures

December 16, 2025
Ford’s CEO said the EV market would be halved without subsidies. Now he’s writing down .5 billion

Ford’s CEO said the EV market would be halved without subsidies. Now he’s writing down $19.5 billion

December 16, 2025
Welcome To Jr. High, GenAI

Welcome To Jr. High, GenAI

December 16, 2025
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Trump turns on CBS, Kushner pulls out and Paramount’s hostile bid for Warner Bros. shows signs of collapse
  • 20 Best Christmas Gift Ideas for Boys (Under $30!)
  • EBRI: 401(k) loans serve as health and housing lifeline
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.