NPM attack update: Hackers pushed malicious packages via phishing, targeting Ethereum, Solana & more. Crashes exposed it early, limiting damage.🔒 Ledger’s CTO warns supply chain threats persist—hardware wallets with clear signing & checks remain the safest defense.h

NPM attack update: Hackers pushed malicious packages via phishing, targeting Ethereum, Solana & more. Crashes exposed it early, limiting damage.🔒 Ledger’s CTO warns supply chain threats persist—hardware wallets with clear signing & checks remain the safest defense.h
𝕏/@P3b7_ •
Revision history

6 recorded changes

Want your article here?

Promote with Leviathan News

On 8 September 2025, attackers carried out a large-scale npm supply chain attack by compromising the account of a prominent maintainer (“qix”) through a targeted phishing email that impersonated npm support and requested a fake 2FA reset. With this access, they published malicious versions of 18 highly popular JavaScript packages, including debug, chalk, ansi-styles, and others that together see over 2.6 billion downloads per week. The tampered releases were live for roughly two hours before the community and security vendors detected suspicious behavior, after which maintainers quickly reverted to clean versions and npm locked impacted accounts. The injected code functioned as a browser-based “crypto-stealer”/wallet drainer designed to intercept and manipulate web3 activity in users’ browsers, silently rewriting wallet interactions and payment destinations for cryptocurrencies such as Ethereum and Solana, as well as other on‑chain approvals. By hooking browser APIs (like fetch and XMLHttpRequest) and common wallet interfaces, the malware could alter transaction targets in the background while preserving a convincing UI, making it difficult for end users to notice that funds or approvals were being redirected to attacker-controlled addresses. Although the short exposure window limited realized damage compared to the worst‑case potential, the incident underscored how quickly a compromised maintainer account can put millions of applications and users at risk and highlighted the systemic fragility of open‑source software supply chains. Security firms and ecosystem participants have emphasized that this campaign is part of a broader pattern of supply chain attacks on web3-related tooling, including prior compromises of npm packages tied to Solana and Ethereum that used blockchain smart contracts to conceal second‑stage commands or steal private key material. In response, experts and vendors—including hardware wallet makers—are stressing defense-in-depth: strict package version pinning and lockfiles, rapid dependency auditing after incidents, strong maintainer account security (particularly phishing-resistant 2FA), and using hardware wallets with clear-signing and robust transaction checks so that even if a web application or dependency is compromised, users still see and must approve the real transaction details on a trusted device before funds can move.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

Comments