The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the… The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the…

NPM Hack Shows Supply Chain Threats Still Endanger Crypto

A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets.

Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.  

If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector. 

Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added. 

Largest NPM attack stole only $50 in crypto 

The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain. 

Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more. 

The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin. 

Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack

TON CTO breaks down NPM attack

Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published. 

Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions.

This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the users. 

He said that developers who pushed their builds within hours of the malicious updates and apps that auto-update their code libraries instead of freezing them to a safe version were the most exposed. 

Makosov shared a checklist on how developers can check if their apps were compromised. The main sign is whether the code is using one of 18 versions of popular libraries like ansi-styles, chalk or debug. He said if a project relies on these versions, it’s likely compromised. 

He said the fix is to switch back to safe versions, reinstall clean code and rebuild applications. He added that new and updated releases are already available and urged developers to act quickly to clear out the malware before it can affect their users. 

Magazine: BTS Jungkook’s hacker, Ripple backs Singapore payments firm: Asia Express

Source: https://cointelegraph.com/news/failed-npm-exploit-crypto-security-threat?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
Threshold Logo
Threshold Price(T)
$0.010099
$0.010099$0.010099
+1.19%
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

UAE and Nigeria sign Cepa to ease trade barriers

UAE and Nigeria sign Cepa to ease trade barriers

The UAE and Nigeria have signed a comprehensive economic partnership agreement (Cepa) to reduce tariffs and trade barriers, with the aim of boosting bilateral commerce
Share
Agbi2026/01/14 14:44
Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
An Exciting New Chapter For Investors

An Exciting New Chapter For Investors

The post An Exciting New Chapter For Investors appeared on BitcoinEthereumNews.com. Coinbase BARD Listing: An Exciting New Chapter For Investors Skip to content Home Crypto News Coinbase BARD Listing: An Exciting New Chapter for Investors Source: https://bitcoinworld.co.in/coinbase-bard-listing-unveiled/
Share
BitcoinEthereumNews2025/09/19 02:10