Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Massive NPM Supply Chain Hack Targets Crypto Wallets but Nets Just $50

Massive NPM Supply Chain Hack Targets Crypto Wallets but Nets Just $50

Cointribune2025/09/09 14:33
By: Cointribune
SOL+1.57%ETH-0.46%BRETT-4.75%

Malicious actors are at it again, this time targeting the account of a well-known software developer’s Node Package Manager (NPM). Investigations revealed that the hackers added malware to popular JavaScript libraries, primarily attacking crypto wallets. However, after launching what industry sleuths describe as the largest supply chain attack in crypto history, the hackers managed to steal only $50 worth of crypto assets.

Massive NPM Supply Chain Hack Targets Crypto Wallets but Nets Just $50 image 0 Massive NPM Supply Chain Hack Targets Crypto Wallets but Nets Just $50 image 1

In brief

  • Hackers compromised popular NPM packages with over 1B downloads, injecting malware that threatened major crypto wallets.
  • Attackers deployed a crypto-clipper to swap wallet addresses, targeting Ethereum and Solana transactions.
  • Despite vast access, hackers stole just $50 worth of ETH and memecoins before the malware was contained.
  • Crypto platforms urged users to stay cautious, warning that projects updating compromised packages may face risks.

Malware in NPM Packages Puts Crypto Wallets at Risk, Targets Ethereum and Solana Wallets

According to the details shared by blockchain intelligence platform Security Alliance on Monday, malicious code sent by the attackers added malware to popular JavaScript libraries with over 1 billion downloads, exposing several crypto projects to risk. The crypto intelligence firm added that the hacker primarily targeted Ethereum and Solana wallets.

For context, NPMs function as central libraries or app stores where developers can download and share small packages to create JavaScript projects. Reports indicate that the hackers appear to have hooked a crypto-clipper , a type of malicious code that silently swaps wallet addresses during transactions to divert funds.

So far, the cybercriminals have succeeded in moving only $50 to a malicious Ethereum wallet. Security Alliance identified the wallet address, labeled “0xFc4a48,” which they believe to be the only compromised wallet.

Widespread NPM Malware Breach Contained After Limited Exploit

Commenting on the breach, pseudonymous SEAL security researcher Samczsun explained that the hacker had significant access but failed to exploit it fully . He added that although the malware was widespread, it has now been largely contained.

The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized. 

Samczsun

However, the current figure of $50 surged from a few cents hours earlier , suggesting that other events related to the hack may still unfold.

Security Alliance reported that five cents’ worth of Ethereum (ETH) and about $20 in memecoins were stolen. According to Etherscan data, the hacker has so far moved Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA).

The hacker’s malware attacked packages such as chalk, strip-ansi, and color-convert—small utilities found deep in dependency trees that have been downloaded over 2 billion times. In fact, the security firm noted that even creators who never installed the program directly could be at risk.

Crypto Platforms Urge Caution After Supply Chain Hack Raises Security Concerns

Ledger chief technology officer Charles Guillemet called for caution among market participants when confirming on-chain transactions. Crypto wallet service providers Ledger and MetaMask maintained that their platforms remain safe from the breach, noting that their wallets are packed with “multiple layers of defense” to guard against such attacks.

Other crypto platforms, including Phantom, Uniswap, Aerodrome, and Blast, noted that they were unaffected by the supply chain hack. However, the founder of the crypto analytics platform DefiLlama, with the pseudonym 0xngmi, detailed that projects that updated after the malicious code-compromised NPM package was published may be exposed to significant risk.

Still, he clarified that users need to approve the malicious transaction before it can go through. However, DefiLlama advised users to avoid using crypto websites until the malware is totally cleaned up. 

With the increased growth of digital assets, crypto hacks have become common in recent years. Crypto platform SwissBorg recently suffered a massive breach , with the hackers moving about 193,000 SOL, worth $41 million.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — ZKC/USDT!
Bitget Announcement2025/09/16 06:28
CandyBomb x ZKC: Trade futures to share 66,666 ZKC!
Bitget Announcement2025/09/16 06:00

Trending news

More
1
Bitget Trading Club Championship (Phase 9)—Trade spot and futures to share 120,000 BGB, up to 2200 BGB per user!
2
New spot margin trading pair — ZKC/USDT!

Crypto prices

More
Bitcoin
Bitcoin
BTC
$116,728.46
+1.13%
Ethereum
Ethereum
ETH
$4,500.03
-0.39%
XRP
XRP
XRP
$3.05
+1.72%
Tether USDt
Tether USDt
USDT
$1
+0.02%
BNB
BNB
BNB
$954.83
+3.70%
Solana
Solana
SOL
$237.74
+1.47%
USDC
USDC
USDC
$0.9999
+0.00%
Dogecoin
Dogecoin
DOGE
$0.2683
+0.54%
TRON
TRON
TRX
$0.3427
-0.55%
Cardano
Cardano
ADA
$0.8789
+1.81%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter