No Result
View All Result
  • Login
Tuesday, December 16, 2025
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Cryptocurrency

Lessons From NPM Crypto Exploit Near-Miss

by FeeOnlyNews.com
3 months ago
in Cryptocurrency
Reading Time: 10 mins read
A A
0
Lessons From NPM Crypto Exploit Near-Miss
Share on FacebookShare on TwitterShare on LInkedIn


A failed attack on popular Node Package Manager (NPM)
libraries sent shockwaves through the crypto world on Monday.

Hackers targeted major packages to hijack
cryptocurrency transactions across multiple blockchains, but due to coding
errors, the breach caused minimal loss.

Still, experts warn that the incident highlights ongoing
risks for software wallets, exchanges, and any platform that automatically
updates code libraries.

NPM Attack Hits Popular Libraries

The attack reportedly started with a phishing email
sent from a fake NPM support domain, which allowed hackers to access developer accounts. Malicious updates were then pushed to libraries, including chalk, debug, and strip-ansi.

The injected code attempted to intercept wallet
addresses on chains like Bitcoin, Ethereum
Ethereum

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,
Read this Term
, Solana, Tron, and Litecoin.

Charles Guillemet, Ledger’s CTO, commented on X: “The
attack fortunately failed, with almost no victims. It began with a phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term

email from a fake npm support domain that stole credentials and gave attackers
access to publish malicious package updates.”

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,… https://t.co/Ud1SBSJ52v pic.twitter.com/lOik6k7Dkp

— Charles Guillemet (@P3b7_) September 9, 2025

According to Guillemet, the injected code targeted web
crypto activity, affecting Ethereum, Solana, and other blockchains, hijacking
transactions and replacing wallet addresses directly in network responses.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

“If your funds sit in a software wallet or on an
exchange, you’re one code execution away from losing everything. Supply-chain
compromises remain a powerful malware delivery vector, and we’re also seeing
more targeted attacks emerge,” he said.

Understanding the Threat

Anatoly Makosov, CTO of The Open Network (TON), also addressed the matter by explaining the mechanics of the attack on X and that only 18 specific package versions were compromised.

Makosov said developers who deployed builds shortly
after the malicious updates, or who rely on auto-updating libraries, were most
exposed. “Developers of multi-chain products should check their code,
especially if they have released something today,” he warned.

⚠️ Attack on popular NPM packages — technical details

A few hours ago, hackers gained access to some NPM accounts and published infected versions of popular libraries.

Many web products use these packages.

Although TON products do not appear to be at risk, developers of…

— Anatoly Makosov (@anatoly_makosov) September 8, 2025

Makosov emphasized that all earlier and newer versions
of the allegedly attacked packages are considered safe. Fixes have been
published, and developers are urged to reinstall clean code and rebuild their
applications.

Minimal Impact, Major Lesson

Despite the sophisticated attempt, the financial
impact was limited. Guillemet credited early detection to errors in the
attackers’ code that caused CI/CD pipeline crashes.

“Hardware wallets are built to withstand these
threats,” Guillemet said. Ledger devices include Clear Signing, letting users
verify transactions on a secure screen, and Transaction Check, which warns of
suspicious activity. “Your private keys and recovery phrase remain safe.
The immediate danger may have passed, but the threat hasn’t. Stay safe,” he
added.

Makosov and Guillemet both emphasized that vigilance
is crucial. Developers should lock dependencies to safe versions and avoid
dynamic updates, while users should avoid blind signing and always verify
wallet addresses.

Meanwhile, crypto wallet provider Ledger has assured
its users that its systems remain safe.

Ledger devices are not and have not been at risk during an ecosystem-wide software supply chain attack that was discovered.

Ledger devices are built specifically to protect users against attacks like these.

Only Ledger devices have secure screens, powered by the Secure Element… https://t.co/cJO2w0dpmU

— Ledger (@Ledger) September 8, 2025

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these,” the company mentioned.

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these.”

Developers have now been urged to examine their
projects’ package files for affected versions and update or rebuild with secure
releases. Users, meanwhile, should avoid blind signing and always verify wallet
addresses before confirming transactions.

A failed attack on popular Node Package Manager (NPM)
libraries sent shockwaves through the crypto world on Monday.

Hackers targeted major packages to hijack
cryptocurrency transactions across multiple blockchains, but due to coding
errors, the breach caused minimal loss.

Still, experts warn that the incident highlights ongoing
risks for software wallets, exchanges, and any platform that automatically
updates code libraries.

NPM Attack Hits Popular Libraries

The attack reportedly started with a phishing email
sent from a fake NPM support domain, which allowed hackers to access developer accounts. Malicious updates were then pushed to libraries, including chalk, debug, and strip-ansi.

The injected code attempted to intercept wallet
addresses on chains like Bitcoin, Ethereum
Ethereum

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,
Read this Term
, Solana, Tron, and Litecoin.

Charles Guillemet, Ledger’s CTO, commented on X: “The
attack fortunately failed, with almost no victims. It began with a phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term

email from a fake npm support domain that stole credentials and gave attackers
access to publish malicious package updates.”

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,… https://t.co/Ud1SBSJ52v pic.twitter.com/lOik6k7Dkp

— Charles Guillemet (@P3b7_) September 9, 2025

According to Guillemet, the injected code targeted web
crypto activity, affecting Ethereum, Solana, and other blockchains, hijacking
transactions and replacing wallet addresses directly in network responses.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

“If your funds sit in a software wallet or on an
exchange, you’re one code execution away from losing everything. Supply-chain
compromises remain a powerful malware delivery vector, and we’re also seeing
more targeted attacks emerge,” he said.

Understanding the Threat

Anatoly Makosov, CTO of The Open Network (TON), also addressed the matter by explaining the mechanics of the attack on X and that only 18 specific package versions were compromised.

Makosov said developers who deployed builds shortly
after the malicious updates, or who rely on auto-updating libraries, were most
exposed. “Developers of multi-chain products should check their code,
especially if they have released something today,” he warned.

⚠️ Attack on popular NPM packages — technical details

A few hours ago, hackers gained access to some NPM accounts and published infected versions of popular libraries.

Many web products use these packages.

Although TON products do not appear to be at risk, developers of…

— Anatoly Makosov (@anatoly_makosov) September 8, 2025

Makosov emphasized that all earlier and newer versions
of the allegedly attacked packages are considered safe. Fixes have been
published, and developers are urged to reinstall clean code and rebuild their
applications.

Minimal Impact, Major Lesson

Despite the sophisticated attempt, the financial
impact was limited. Guillemet credited early detection to errors in the
attackers’ code that caused CI/CD pipeline crashes.

“Hardware wallets are built to withstand these
threats,” Guillemet said. Ledger devices include Clear Signing, letting users
verify transactions on a secure screen, and Transaction Check, which warns of
suspicious activity. “Your private keys and recovery phrase remain safe.
The immediate danger may have passed, but the threat hasn’t. Stay safe,” he
added.

Makosov and Guillemet both emphasized that vigilance
is crucial. Developers should lock dependencies to safe versions and avoid
dynamic updates, while users should avoid blind signing and always verify
wallet addresses.

Meanwhile, crypto wallet provider Ledger has assured
its users that its systems remain safe.

Ledger devices are not and have not been at risk during an ecosystem-wide software supply chain attack that was discovered.

Ledger devices are built specifically to protect users against attacks like these.

Only Ledger devices have secure screens, powered by the Secure Element… https://t.co/cJO2w0dpmU

— Ledger (@Ledger) September 8, 2025

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these,” the company mentioned.

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these.”

Developers have now been urged to examine their
projects’ package files for affected versions and update or rebuild with secure
releases. Users, meanwhile, should avoid blind signing and always verify wallet
addresses before confirming transactions.





Source link

Tags: CryptoexploitLessonsnearmissNPM
ShareTweetShare
Previous Post

Amsterdam’s Nebius shares soar 51% after sealing €16.5B AI infrastructure deal with Microsoft

Next Post

Cassidy Raises $10M to Scale Context-Powered AI Automation for Non-Technical Teams – AlleyWatch

Related Posts

Dogecoin Price Squeeze Maps Out Two Possible Scenarios From Here

Dogecoin Price Squeeze Maps Out Two Possible Scenarios From Here

by FeeOnlyNews.com
December 16, 2025
0

Crypto analyst Erick Crypto has highlighted a Dogecoin price squeeze, which is currently playing out. Based on this, he mentioned...

The Winklevoss Twins Just Launched Gemini Predictions in the US

The Winklevoss Twins Just Launched Gemini Predictions in the US

by FeeOnlyNews.com
December 16, 2025
0

Gemini started offering prediction markets across the United States this week, capping a five-year effort to secure federal approval and...

Libra’s Launch Was Calculated: New Revelations Hint at Milei’s Involvement

Libra’s Launch Was Calculated: New Revelations Hint at Milei’s Involvement

by FeeOnlyNews.com
December 16, 2025
0

A local media article alleges that Mauricio Novelli and Manuel Terrones Godoy, two crypto entrepreneurs, were present when Libra was...

Bitcoin Outperforms Altcoins Despite Market-Wide Decline

Bitcoin Outperforms Altcoins Despite Market-Wide Decline

by FeeOnlyNews.com
December 16, 2025
0

Despite a decline from all-time highs, Bitcoin has still performed better than most other cryptocurrency sectors in recent months, indicating...

Trump open to reviewing pardon for Samourai Bitcoin app developer

Trump open to reviewing pardon for Samourai Bitcoin app developer

by FeeOnlyNews.com
December 15, 2025
0

Key Takeaways Trump expressed willingness to consider a pardon for Samourai Wallet developer Keonne Rodriguez. The case highlights tensions between...

Ethereum Activity Hits 7-Month Low: Active Addresses Drop 32% From August Peak

Ethereum Activity Hits 7-Month Low: Active Addresses Drop 32% From August Peak

by FeeOnlyNews.com
December 15, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ethereum is struggling to regain traction as...

Next Post
Cassidy Raises M to Scale Context-Powered AI Automation for Non-Technical Teams – AlleyWatch

Cassidy Raises $10M to Scale Context-Powered AI Automation for Non-Technical Teams – AlleyWatch

Mortgage Rates Today, Tuesday, September 9: Noticeably Lower

Mortgage Rates Today, Tuesday, September 9: Noticeably Lower

  • Trending
  • Comments
  • Latest
Newsom, DeSantis join forces to blast ‘idiotic’ push to allow oil drilling off coasts of California, Florida

Newsom, DeSantis join forces to blast ‘idiotic’ push to allow oil drilling off coasts of California, Florida

November 23, 2025
Israeli housing rental platform Venn raises m

Israeli housing rental platform Venn raises $52m

November 18, 2025
What is a credit card spending limit — and what to know

What is a credit card spending limit — and what to know

August 4, 2025
Links 12/10/2025 | naked capitalism

Links 12/10/2025 | naked capitalism

December 10, 2025
5 Senior Discounts Being Eliminated by National Retailers

5 Senior Discounts Being Eliminated by National Retailers

December 7, 2025
AT&T promised the government it won’t pursue DEI

AT&T promised the government it won’t pursue DEI

December 4, 2025
Vijay Kedia buys 9 lakh shares of SME stock Mahamaya Lifesciences in Rs 12.5 crore block deal

Vijay Kedia buys 9 lakh shares of SME stock Mahamaya Lifesciences in Rs 12.5 crore block deal

0
US Dollar Maintains a Bearish Structure Ahead of NFP

US Dollar Maintains a Bearish Structure Ahead of NFP

0
Best Ways to Minimize Investment Risk Management

Best Ways to Minimize Investment Risk Management

0
Heating Assistance Programs Are Closing Earlier Than Expected

Heating Assistance Programs Are Closing Earlier Than Expected

0
Urogen Pharma – URGN: Die neue Medikation gegen Blasenkrebs sorgt für Momentum!

Urogen Pharma – URGN: Die neue Medikation gegen Blasenkrebs sorgt für Momentum!

0
Hassett says Fed independence is ‘really important’ and chair candidates shouldn’t be disqualified for being Trump’s friend

Hassett says Fed independence is ‘really important’ and chair candidates shouldn’t be disqualified for being Trump’s friend

0
Vijay Kedia buys 9 lakh shares of SME stock Mahamaya Lifesciences in Rs 12.5 crore block deal

Vijay Kedia buys 9 lakh shares of SME stock Mahamaya Lifesciences in Rs 12.5 crore block deal

December 16, 2025
Trump has ‘an alcoholic’s personality, chief of staff says in wide-ranging Vanity Fair interview. She calls it a ‘hit piece’

Trump has ‘an alcoholic’s personality, chief of staff says in wide-ranging Vanity Fair interview. She calls it a ‘hit piece’

December 16, 2025
Hassett says Fed independence is ‘really important’ and chair candidates shouldn’t be disqualified for being Trump’s friend

Hassett says Fed independence is ‘really important’ and chair candidates shouldn’t be disqualified for being Trump’s friend

December 16, 2025
Lending startup backed by Altman, JPMorgan teams up with Amazon

Lending startup backed by Altman, JPMorgan teams up with Amazon

December 16, 2025
Nvidia to pay NIS 90m for Kiryat Tivon site

Nvidia to pay NIS 90m for Kiryat Tivon site

December 16, 2025
Heating Assistance Programs Are Closing Earlier Than Expected

Heating Assistance Programs Are Closing Earlier Than Expected

December 16, 2025
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Vijay Kedia buys 9 lakh shares of SME stock Mahamaya Lifesciences in Rs 12.5 crore block deal
  • Trump has ‘an alcoholic’s personality, chief of staff says in wide-ranging Vanity Fair interview. She calls it a ‘hit piece’
  • Hassett says Fed independence is ‘really important’ and chair candidates shouldn’t be disqualified for being Trump’s friend
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.