financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Crypto
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Crypto
Sep 9, 2025 3:06 PM

The NPM (node packet manager) account of developer qix was compromised, allowing hackers to publish malicious versions of his packages.

The attackers published malicious versions of dozens of extremely popular JavaScript packages, including fundamental utilities. The hack was massive in scope since the affected packages have over 1 billion combined weekly downloads.

This attack on the software supply chain specifically targets the JavaScript/Node.js ecosystem.

NPM Supply Chain Attack

Popular dev qix fell victim to phishing. Malicious code injected into npm packages now hijacks crypto transactions at signing.

Attack method:

• Hooks wallet functions (request/send)

• Swaps recipient addresses in ETH/SOL transactions

• Replaces… pic.twitter.com/Jn9H4HWP8v

Crypto Clipper Malware

The malicious code was a “crypto-clipper” designed to steal cryptocurrency by swapping wallet addresses in network requests and hijacking crypto transactions directly. It was also heavily obfuscated to avoid detection.

The crypto-stealing malware has two attack vectors. When no crypto wallet extension is found, the malware intercepts all network traffic by replacing the browser’s native fetch and HTTP request functions with extensive lists of attacker-owned wallet addresses.

Using sophisticated address swapping, it employs algorithms to find replacement addresses that look visually similar to legitimate ones, making the fraud nearly impossible to spot with the naked eye, said cybersecurity researchers.

If a crypto wallet is found, the malware intercepts transactions before signing, and when users initiate transactions, it modifies them in memory to redirect funds to attacker addresses.

The attack targeted packages such as ‘chalk,’ ‘strip-ansi,’ ‘color-convert,’ and ‘color-name,’ which are core building blocks buried deep in the dependency trees of countless projects.

The attack was discovered accidentally when a build pipeline failed with a “fetch is not defined” error as the malware attempted to exfiltrate data using the fetch function.

“If you use a hardware wallet, pay attention to every transaction before signing, and youre safe. If you don’t use a hardware wallet, refrain from making any on-chain transactions for now,” advised Ledger CEO Charles Guillemet.

Explanation of the current npm hack

In any website that uses this hacked dependency, it gives a chance to the hacker to inject malicious code, so for example when you click a swap button on a website, the code might replace the tx sent to your wallet with a tx sending money to…

Broad Attack Vector

While the malware’s payload specifically targets cryptocurrency, the attack vector is much broader. It affects any environment running JavaScript/Node.js applications, such as web applications running in browsers, desktop applications, server-side Node.js applications, and mobile apps using JavaScript frameworks.

So a regular business web application could unknowingly include these malicious packages, but the malware would only activate when users interact with cryptocurrency on that site.

Uniswap and Blockstream were among the first to reassure users that their systems were not at risk.

Regarding the reports of the NPM supply chain attack:

Uniswap apps are not at risk

Our team has confirmed that we do not use any vulnerable versions of the affected packages

As always, be vigilant

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Montenegro’s Court of Appeal Upholds Ruling on Do Kwon’s Extradition to South Korea
Montenegro’s Court of Appeal Upholds Ruling on Do Kwon’s Extradition to South Korea
Mar 21, 2024
After a series of back-and-forths regarding Do Kwons extradition, it appears that the Terraform Labs co-founder and former CEO may finally be handed over to South Korean authorities after the Appellate Court of Montenegro confirmed a previous decision to extradite him to his native country. Terraform Labs’ Chief Executive Officer, who was arrested in March 2023 with Kwon in Montenegro,...
Bitcoin Struggles at $66K; Ripple’s XRP Defies Bearish Momentum (Market Watch)
Bitcoin Struggles at $66K; Ripple’s XRP Defies Bearish Momentum (Market Watch)
Mar 22, 2024
The cryptocurrency market has failed to recover as swiftly as many expected it to, and Bitcoins price seems to be struggling to break above $66K definitively. Most of the altcoins are also trading in the red, with two notable exceptions. Bitcoin Fails at $66K As seen in the chart below, Bitcoins price was unable to retain its bullish momentum that...
This Trending Meme Coin Explodes 50% Daily: Details
This Trending Meme Coin Explodes 50% Daily: Details
Mar 22, 2024
TL;DR Meme coins on the Solana blockchain have shown potential for high profits, with instances of substantial investment returns highlighted. Despite these opportunities, the inherent volatility of meme coins underscores a considerable risk of losses. Meme coins built on the Solana blockchain have been thriving in the past several months, with the sector spewing new ones quite frequently. Todays best...
Cardano on the Verge of Achieving a Massive Milestone: ADA Bull Run Imminent?
Cardano on the Verge of Achieving a Massive Milestone: ADA Bull Run Imminent?
Mar 22, 2024
Cardano (ADA) is showing strong growth in smart contract development. Since the beginning of the year, the number of Plutus scripts on the Cardano network, including Plutus V1 and V2, has surged by 171.45%,  At this pace, the Cardano network is adding nearly 500 new smart contracts daily. According to data from Cardano Blockchain Insights, the network has achieved 39,000...
Copyright 2023-2026 - www.financetom.com All Rights Reserved