BTCC / BTCC Square / Global Cryptocurrency /
NPM Supply Chain Attack Targets Crypto Users Through JavaScript Package Compromise

NPM Supply Chain Attack Targets Crypto Users Through JavaScript Package Compromise

Published:
2025-09-09 09:59:02
15
3
BTCCSquare news:

A significant supply chain attack has compromised 18 popular Node.js packages, including widely-used libraries like chalk, debug, and strip-ansi. These packages collectively account for over 2 billion weekly downloads, marking one of the largest npm breaches to date.

The malware operates as a crypto clipper, stealthily replacing wallet addresses during transactions to divert funds to attacker-controlled accounts. The breach originated when developer "qix" fell victim to a phishing email impersonating NPM support, granting hackers access to inject malicious code.

Despite the attack's massive potential reach—affecting major protocols like Uniswap, Jupiter, and MetaMask—only $497 has been stolen so far. Hardware wallet users remain protected due to device-level transaction confirmation requirements.

Security experts emphasize this event underscores the growing sophistication of attacks targeting cryptocurrency users through developer ecosystems. The JavaScript community is urged to review dependencies and implement additional verification measures.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users