Sunday, November 16, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Largest supply chain attack in history targets crypto users through compromised JavaScript packages

by DigestWire member
September 8, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
Largest supply chain attack in history targets crypto users through compromised JavaScript packages
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

A new cyberattack is silently targeting crypto from users during transactions amid an incident that security researchers describe as the largest supply chain attack in history.

BleepingComputer reported that hackers compromised NPM package maintainer accounts through phishing emails and injected malware that steals crypto.

The attack targeted JavaScript developers with fraudulent emails appearing to originate from “[email protected],” an impersonated domain mimicking the legitimate NPM registry.

The phishing messages warned maintainers that their accounts would be locked on Sept. 10, unless they updated their two-factor authentication credentials through a malicious link.

Attackers successfully compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries include fundamental development tools such as “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting virtually the entire JavaScript ecosystem.

Targeting crypto

The malicious code operates as a browser-based interceptor, monitoring network traffic for crypto transactions across Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash networks.

When users initiate crypto transfers, the malware silently replaces destination wallet addresses with attacker-controlled accounts before transaction signing.

Aikido Security researcher Charlie Eriksen explained:

“What makes it dangerous is that it operates at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

Ledger CTO Charles Guillemet warned crypto users about the ongoing threat, noting the JavaScript ecosystem may be compromised given the massive download figures.

Hardware wallet users retain protection if they verify transaction details before signing, while software wallet users face a higher risk. Guillemet advised:

“If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.”

He also noted uncertainty about whether attackers can directly extract seed phrases from software wallets.

Sophisticated targeting

The attack represents a sophisticated supply chain targeting where criminals compromise trusted development infrastructure to reach end users.

By infiltrating packages downloaded billions of times weekly, attackers gained unprecedented access to cryptocurrency applications and wallet interfaces.

BleepingComputer identified the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows similar JavaScript library compromises throughout 2025, including the July attack on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten popular NPM libraries.

The post Largest supply chain attack in history targets crypto users through compromised JavaScript packages appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post

Pundit Says ‘Ethereum Is Dying’ As Fundamentals Collapse By Over 40% — Details

Altcoins Feel The Pinch As Crypto Market Sentiment Sours

New Banksy artwork to be removed from Royal Courts of Justice

New Banksy artwork to be removed from Royal Courts of Justice

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Blackrock’s BUIDL Enters Binance Ecosystem With Expanding Onchain Institutional Reach

Shubman Gill under observation, out of remainder of Eden Gardens Test

Vermont beats UMaine hockey 2-1 to deny Black Bears sweep

Temperatures could fall to -7C as cold snap follows Storm Claudia

Pope Leo meets with film stars and directors at Vatican

Sherlock star’s ‘very odd’ new role opposite seven-foot bird in portrait of male grief

Trending

Devine three-for takes Scorchers past Strikers in rain-hit game
Cricket

Devine three-for takes Scorchers past Strikers in rain-hit game

by DigestWire member
November 16, 2025
0

Scorchers were 55 for 2, nine runs clear of the DLS target, when rain ended their chase...

Glen Powell Brings His UPS Driver to Crash ‘SNL’ Monologue: ‘He Thought It Was a Scam, But He Still Came’

Glen Powell Brings His UPS Driver to Crash ‘SNL’ Monologue: ‘He Thought It Was a Scam, But He Still Came’

November 16, 2025
XRP ETF Price Crash Explained

XRP ETF Price Crash Explained

November 16, 2025
Blackrock’s BUIDL Enters Binance Ecosystem With Expanding Onchain Institutional Reach

Blackrock’s BUIDL Enters Binance Ecosystem With Expanding Onchain Institutional Reach

November 16, 2025
Shubman Gill under observation, out of remainder of Eden Gardens Test

Shubman Gill under observation, out of remainder of Eden Gardens Test

November 16, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Devine three-for takes Scorchers past Strikers in rain-hit game November 16, 2025
  • Glen Powell Brings His UPS Driver to Crash ‘SNL’ Monologue: ‘He Thought It Was a Scam, But He Still Came’ November 16, 2025
  • XRP ETF Price Crash Explained November 16, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.