BTCC / BTCC Square / Global Cryptocurrency /
New Security Flaw Threatens Crypto and Online Services

New Security Flaw Threatens Crypto and Online Services

Published:
2025-09-09 13:18:02
6
1
BTCCSquare news:

The crypto ecosystem faces one of its most sophisticated attacks to date. A compromised NPM developer account led to the injection of malicious code into widely used JavaScript modules, including popular packages like 'chalk' and 'strip-ansi'. The malware, a 'crypto-clipper,' silently alters wallet addresses during transactions, redirecting funds to attackers.

Security experts warn that only hardware wallets provide effective protection against this breach. The attack, which unfolded on September 8, 2025, highlights the vulnerabilities in the software supply chain. NPM, a critical infrastructure for web development, distributes over a billion modules weekly, making the impact potentially catastrophic.

Thousands of projects—ranging from websites to cloud services—are now exposed. The breach underscores the need for heightened vigilance in open-source ecosystems, where a single point of failure can Ripple across the entire digital landscape.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users