The post NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries appeared on BitcoinEthereumNews.com. Hackers have compromised widely used JavaScript software libraries in what’s being called the largest supply chain attack in history. The injected malware is reportedly designed to steal crypto by swapping wallet addresses and intercepting transactions. According to several reports on Monday, hackers broke into the node package manager (NPM) account of a well-known developer and secretly added malware to popular JavaScript libraries used by millions of apps. The malicious code swaps or hijacks crypto wallet addresses, potentially putting many projects at risk. “There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised,” Ledger chief technology officer Charles Guillemet warned on Monday. “The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.” Source: Minal Thukral The breach targeted packages such as chalk, strip-ansi and color-convert — small utilities buried deep in the dependency trees of countless projects. Together, these libraries are downloaded more than a billion times each week, meaning even developers who never installed them directly could be exposed. NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects. Attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds. Security researchers warned that users relying on software wallets may be especially vulnerable, while those confirming every transaction on a hardware wallet are protected. Users warned to avoid crypto transactions According to a X post by DefiLlama founder Oxngmi, the malicious code doesn’t automatically drain wallets — users would still have to approve a bad transaction.  Since the hacked JavaScript package can alter what happens when you click a button, hitting the “swap” button on an affected site could swap out the transaction details and send funds to… The post NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries appeared on BitcoinEthereumNews.com. Hackers have compromised widely used JavaScript software libraries in what’s being called the largest supply chain attack in history. The injected malware is reportedly designed to steal crypto by swapping wallet addresses and intercepting transactions. According to several reports on Monday, hackers broke into the node package manager (NPM) account of a well-known developer and secretly added malware to popular JavaScript libraries used by millions of apps. The malicious code swaps or hijacks crypto wallet addresses, potentially putting many projects at risk. “There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised,” Ledger chief technology officer Charles Guillemet warned on Monday. “The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.” Source: Minal Thukral The breach targeted packages such as chalk, strip-ansi and color-convert — small utilities buried deep in the dependency trees of countless projects. Together, these libraries are downloaded more than a billion times each week, meaning even developers who never installed them directly could be exposed. NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects. Attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds. Security researchers warned that users relying on software wallets may be especially vulnerable, while those confirming every transaction on a hardware wallet are protected. Users warned to avoid crypto transactions According to a X post by DefiLlama founder Oxngmi, the malicious code doesn’t automatically drain wallets — users would still have to approve a bad transaction.  Since the hacked JavaScript package can alter what happens when you click a button, hitting the “swap” button on an affected site could swap out the transaction details and send funds to…

NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries

3 min read

Hackers have compromised widely used JavaScript software libraries in what’s being called the largest supply chain attack in history. The injected malware is reportedly designed to steal crypto by swapping wallet addresses and intercepting transactions.

According to several reports on Monday, hackers broke into the node package manager (NPM) account of a well-known developer and secretly added malware to popular JavaScript libraries used by millions of apps.

The malicious code swaps or hijacks crypto wallet addresses, potentially putting many projects at risk.

“There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised,” Ledger chief technology officer Charles Guillemet warned on Monday. “The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.”

Source: Minal Thukral

The breach targeted packages such as chalk, strip-ansi and color-convert — small utilities buried deep in the dependency trees of countless projects. Together, these libraries are downloaded more than a billion times each week, meaning even developers who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Security researchers warned that users relying on software wallets may be especially vulnerable, while those confirming every transaction on a hardware wallet are protected.

Users warned to avoid crypto transactions

According to a X post by DefiLlama founder Oxngmi, the malicious code doesn’t automatically drain wallets — users would still have to approve a bad transaction. 

Since the hacked JavaScript package can alter what happens when you click a button, hitting the “swap” button on an affected site could swap out the transaction details and send funds to the hacker instead. 

He added that only projects that were updated after the compromised package was published are at risk, and many developers “pin” their dependencies so they keep using older, safe versions.

Still, because users can’t easily tell which sites were updated safely, it’s best to avoid using crypto websites until the affected packages are cleaned up.

Source: Oxngmi

Phishing emails gave attackers access to NPM maintainer accounts

Attackers sent emails posing as official NPM support, warning maintainers that their accounts would be locked unless they “updated” two-factor authentication by Sept. 10.

The fake site captured login credentials, giving hackers control over a maintainer’s account. Once inside, the attackers pushed malicious updates to packages with billions of weekly downloads.

Charlie Eriksen, a researcher at Aikido Security, told BleepingComputer the attack was especially dangerous because it operated “at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

Phishing email sent to JavaScript developers on Monday. Source: Github/Burnett01

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users

Source: https://cointelegraph.com/news/npm-attack-crypto-stealing-malware-into-core-javascript-libraries?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Unleash Potential: Flare Network’s FXRP Revolutionizes DeFi Access for XRP

Unleash Potential: Flare Network’s FXRP Revolutionizes DeFi Access for XRP

BitcoinWorld Unleash Potential: Flare Network’s FXRP Revolutionizes DeFi Access for XRP The world of decentralized finance (DeFi) is constantly evolving, and a major new development is set to excite XRP enthusiasts. Flare Network has just launched FXRP, an innovative solution designed to bring XRP directly into the heart of DeFi applications. This move opens up a wealth of new possibilities for XRP holders, allowing them to engage with lending, borrowing, and trading platforms like never before. It’s a significant step towards a more interconnected crypto ecosystem. What is FXRP and Why is it a Game-Changer for XRP? At its core, FXRP is an over-collateralized, wrapped version of XRP. Think of it as a digital twin of XRP, but one that lives on the Flare Network. This design is crucial because XRP itself doesn’t natively support smart contracts in the same way that Ethereum or other DeFi-centric blockchains do. Consequently, XRP has largely been excluded from the burgeoning DeFi sector. However, FXRP changes this narrative completely. By wrapping XRP, Flare Network creates a token that can interact with smart contracts on its own blockchain. This means XRP holders can now: Access a wider range of DeFi protocols. Participate in decentralized lending and borrowing. Engage in yield farming opportunities. Trade their XRP on decentralized exchanges. This initiative transforms XRP from a primarily transactional asset into a more versatile, programmable one within the DeFi landscape. How Can You Acquire and Utilize FXRP? Getting your hands on FXRP is straightforward, offering flexibility for users. You have two primary methods to acquire this wrapped token. First, users can mint FXRP directly on the Flare Network. This process typically involves locking up an equivalent amount of XRP as collateral, ensuring the wrapped token remains fully backed. Alternatively, if direct minting isn’t your preference, you can acquire FXRP on various decentralized exchanges (DEXs). Platforms like SparkDEX, BlazeSwap, and Enosys are among the initial venues where you can trade for FXRP. This accessibility makes it easy for existing DeFi users and new participants alike to join the Flare Network ecosystem and explore its offerings. The over-collateralization aspect adds an extra layer of security, providing confidence in the token’s backing. Expanding DeFi Horizons: The Broader Impact of FXRP The introduction of FXRP extends far beyond just enabling XRP holders to participate in DeFi. It has a much broader impact on the entire decentralized finance ecosystem. By integrating a widely adopted asset like XRP, Flare Network significantly boosts the total value locked (TVL) and liquidity available within DeFi. This influx of capital and users can lead to more robust and efficient markets. Moreover, FXRP positions Flare Network as a vital bridge between different blockchain ecosystems. It demonstrates how assets from one chain can gain new functionality and utility on another, fostering greater interoperability. This cross-chain capability is essential for the long-term growth and sustainability of decentralized finance, as it breaks down silos and encourages a more unified digital economy. The potential for future integrations with other tokens and protocols is immense, further solidifying Flare’s role. Navigating the Challenges and Future of FXRP While the launch of FXRP presents exciting opportunities, it’s also important to consider potential challenges. As with any new technology in the crypto space, security remains a paramount concern. The integrity of the wrapping mechanism and the underlying smart contracts must be rigorously maintained. Furthermore, user adoption and education will be key to the success of FXRP. New users need clear guidance on how to safely mint, acquire, and use the token in various DeFi applications. The competitive landscape also plays a role; other wrapped assets exist, and FXRP must demonstrate its unique value proposition. However, with its strong backing and the innovative approach of Flare Network, FXRP is well-positioned for growth. Its ability to unlock XRP’s potential for DeFi is a powerful differentiator, promising a vibrant future for both the token and the network. Actionable Insights: Getting Started with FXRP in DeFi If you’re an XRP holder looking to explore the new opportunities presented by FXRP, here are some actionable insights to help you get started: Do Your Research: Before engaging with any DeFi platform, thoroughly research its reputation, security audits, and user reviews. Understand how FXRP interacts with specific protocols. Understand the Risks: DeFi carries inherent risks, including smart contract vulnerabilities, impermanent loss, and market volatility. Familiarize yourself with these risks before committing funds. Start Small: Consider starting with a small amount of FXRP to familiarize yourself with the process of minting, acquiring, and using it in DeFi applications. Stay Informed: Follow official Flare Network channels and reputable crypto news sources to stay updated on new integrations, security announcements, and community developments related to FXRP. By taking these steps, you can confidently navigate the exciting new world that FXRP opens up for XRP within decentralized finance. In conclusion, the launch of FXRP by Flare Network is a monumental step forward for the XRP community and the broader DeFi ecosystem. It effectively bridges a gap, allowing one of the most widely held cryptocurrencies to participate actively in decentralized finance. This innovation not only expands the utility of XRP but also reinforces Flare Network’s commitment to building a more interconnected and functional blockchain world. As FXRP gains traction, we can expect to see a surge in innovative DeFi applications and a more vibrant, inclusive financial landscape for all. Frequently Asked Questions (FAQs) Q1: What exactly is FXRP? A1: FXRP is an over-collateralized, wrapped version of XRP, specifically designed to enable XRP holders to use their assets within decentralized finance (DeFi) applications on the Flare Network. Q2: How is FXRP different from standard XRP? A2: While FXRP is backed by XRP, its key difference is that it resides on the Flare Network and is compatible with smart contracts. This allows it to be used in DeFi protocols for lending, borrowing, and trading, which standard XRP cannot do natively. Q3: Where can I acquire FXRP? A3: You can acquire FXRP by minting it directly on the Flare Network by locking up XRP, or by purchasing it on decentralized exchanges such as SparkDEX, BlazeSwap, and Enosys. Q4: What are the main benefits of using FXRP in DeFi? A4: The primary benefits include gaining access to a wide array of DeFi services like lending, borrowing, and trading on DEXs, thereby increasing the utility and potential earning opportunities for XRP holders within the decentralized ecosystem. Q5: What is Flare Network’s role in the creation of FXRP? A5: Flare Network is the blockchain platform that hosts FXRP. It provides the smart contract functionality and infrastructure necessary to wrap XRP and enable its use in DeFi applications, acting as a bridge for XRP into the decentralized world. If you found this article insightful and believe in the potential of FXRP to revolutionize DeFi, please share it with your network! Help spread the word about how Flare Network is bridging the gap for XRP holders and expanding the possibilities within decentralized finance. Your support helps grow our community and keeps everyone informed about the latest crypto innovations. To learn more about the latest crypto market trends, explore our article on key developments shaping decentralized finance institutional adoption. This post Unleash Potential: Flare Network’s FXRP Revolutionizes DeFi Access for XRP first appeared on BitcoinWorld.
Share
Coinstats2025/09/24 22:45
Fed Lowers Rates By 25bps: How Bitcoin And Crypto Prices Responded And What’s Next

Fed Lowers Rates By 25bps: How Bitcoin And Crypto Prices Responded And What’s Next

The Federal Reserve (Fed) announced its first interest rate cut of the year, leading to an immediate reaction in the cryptocurrency market. Bitcoin (BTC) experienced a notable decline, dropping below the $115,000 threshold shortly after the announcement.  Expert Predicts Crypto Rally Fed Chair Jerome Powell addressed the current economic landscape, noting that while inflation has […]
Share
Bitcoinist2025/09/18 03:11
XRP Price Outlook As Peter Brandt Predicts BTC Price Might Crash to $42k

XRP Price Outlook As Peter Brandt Predicts BTC Price Might Crash to $42k

The post XRP Price Outlook As Peter Brandt Predicts BTC Price Might Crash to $42k appeared on BitcoinEthereumNews.com. XRP price led cryptocurrency losses on Friday
Share
BitcoinEthereumNews2026/02/06 19:06