The post DuckDB NPM Account Hack Leads to New Malware Release appeared on BitcoinEthereumNews.com. Key Points: DuckDB NPM account hacked, malicious packages released with wallet-draining malware. Community warned of similar attacks seen previously. Immediate actions taken to mitigate risks and alert developers. SlowMist’s CISO 23pds reported a DuckDB NPM account compromise on September 9, releasing malware-laden versions of duckdb and duckdb-wasm, raising significant security concerns. The compromise poses a risk of cryptocurrency wallet theft, highlighting vulnerabilities in open-source supply chains and prompting developers to reassess security protocols. DuckDB Breach Exposes Critical Supply Chain Vulnerabilities 23pds from SlowMist announced that the DuckDB NPM account had been compromised. Malicious versions of duckdb and related packages were released early, containing wallet-draining malware. The official DuckDB project maintainers quickly marked affected packages as deprecated on their GitHub. The malware targeted developer systems, redirecting cryptocurrency transactions. Affected assets included Ethereum, Bitcoin, Solana, and Litecoin. The incident did not impact DeFi smart contracts directly. 23pds, Chief Information Security Officer, SlowMist Technology, remarked, “The DuckDB NPM account was compromised and malicious code was published. Be attentive to wallet-draining attacks similar to those seen in previous supply chain incidents.” Industry experts issued strong responses. SlowMist warned against increased vulnerabilities in developer environments. Vercel’s security team confirmed malicious code intercepted cryptocurrency interactions. No significant on-chain theft reported. Historical Attacks Highlight Continued Risks in Package Management Did you know? Historical supply chain attacks like the June 2025 NPM compromises targeted major packages, posing systemic security risks that persist in today’s digital infrastructure. Ethereum, trading at $4,282.35, holds a market dominance of 13.40% with a market cap of $516.90 billion, as per CoinMarketCap. Despite a 1.88% drop over 24 hours, Ethereum shows a 43.03% price surge over 60 days. The 24-hour trading volume stands at $33.75 billion, up by 18.83%. Ethereum(ETH), daily chart, screenshot on CoinMarketCap at 15:38 UTC on September 9, 2025. Source: CoinMarketCap… The post DuckDB NPM Account Hack Leads to New Malware Release appeared on BitcoinEthereumNews.com. Key Points: DuckDB NPM account hacked, malicious packages released with wallet-draining malware. Community warned of similar attacks seen previously. Immediate actions taken to mitigate risks and alert developers. SlowMist’s CISO 23pds reported a DuckDB NPM account compromise on September 9, releasing malware-laden versions of duckdb and duckdb-wasm, raising significant security concerns. The compromise poses a risk of cryptocurrency wallet theft, highlighting vulnerabilities in open-source supply chains and prompting developers to reassess security protocols. DuckDB Breach Exposes Critical Supply Chain Vulnerabilities 23pds from SlowMist announced that the DuckDB NPM account had been compromised. Malicious versions of duckdb and related packages were released early, containing wallet-draining malware. The official DuckDB project maintainers quickly marked affected packages as deprecated on their GitHub. The malware targeted developer systems, redirecting cryptocurrency transactions. Affected assets included Ethereum, Bitcoin, Solana, and Litecoin. The incident did not impact DeFi smart contracts directly. 23pds, Chief Information Security Officer, SlowMist Technology, remarked, “The DuckDB NPM account was compromised and malicious code was published. Be attentive to wallet-draining attacks similar to those seen in previous supply chain incidents.” Industry experts issued strong responses. SlowMist warned against increased vulnerabilities in developer environments. Vercel’s security team confirmed malicious code intercepted cryptocurrency interactions. No significant on-chain theft reported. Historical Attacks Highlight Continued Risks in Package Management Did you know? Historical supply chain attacks like the June 2025 NPM compromises targeted major packages, posing systemic security risks that persist in today’s digital infrastructure. Ethereum, trading at $4,282.35, holds a market dominance of 13.40% with a market cap of $516.90 billion, as per CoinMarketCap. Despite a 1.88% drop over 24 hours, Ethereum shows a 43.03% price surge over 60 days. The 24-hour trading volume stands at $33.75 billion, up by 18.83%. Ethereum(ETH), daily chart, screenshot on CoinMarketCap at 15:38 UTC on September 9, 2025. Source: CoinMarketCap…

DuckDB NPM Account Hack Leads to New Malware Release

Key Points:
  • DuckDB NPM account hacked, malicious packages released with wallet-draining malware.
  • Community warned of similar attacks seen previously.
  • Immediate actions taken to mitigate risks and alert developers.

SlowMist’s CISO 23pds reported a DuckDB NPM account compromise on September 9, releasing malware-laden versions of duckdb and duckdb-wasm, raising significant security concerns.

The compromise poses a risk of cryptocurrency wallet theft, highlighting vulnerabilities in open-source supply chains and prompting developers to reassess security protocols.

DuckDB Breach Exposes Critical Supply Chain Vulnerabilities

23pds from SlowMist announced that the DuckDB NPM account had been compromised. Malicious versions of duckdb and related packages were released early, containing wallet-draining malware. The official DuckDB project maintainers quickly marked affected packages as deprecated on their GitHub.

The malware targeted developer systems, redirecting cryptocurrency transactions. Affected assets included Ethereum, Bitcoin, Solana, and Litecoin. The incident did not impact DeFi smart contracts directly.

23pds, Chief Information Security Officer, SlowMist Technology, remarked, “The DuckDB NPM account was compromised and malicious code was published. Be attentive to wallet-draining attacks similar to those seen in previous supply chain incidents.”

Industry experts issued strong responses. SlowMist warned against increased vulnerabilities in developer environments. Vercel’s security team confirmed malicious code intercepted cryptocurrency interactions. No significant on-chain theft reported.

Historical Attacks Highlight Continued Risks in Package Management

Did you know? Historical supply chain attacks like the June 2025 NPM compromises targeted major packages, posing systemic security risks that persist in today’s digital infrastructure.

Ethereum, trading at $4,282.35, holds a market dominance of 13.40% with a market cap of $516.90 billion, as per CoinMarketCap. Despite a 1.88% drop over 24 hours, Ethereum shows a 43.03% price surge over 60 days. The 24-hour trading volume stands at $33.75 billion, up by 18.83%.

Ethereum(ETH), daily chart, screenshot on CoinMarketCap at 15:38 UTC on September 9, 2025. Source: CoinMarketCap

The Coincu research team noted that such compromises urge developers to increase supply chain security measures. With digital finances expanding, reliance on open-source projects necessitates refined scrutiny and vigilance against phishing schemes, emphasizing sustained awareness across all digital layers.

Source: https://coincu.com/scam-alert/duckdb-npm-account-compromised-malware/

Market Opportunity
Capverse Logo
Capverse Price(CAP)
$0.13103
$0.13103$0.13103
-1.39%
USD
Capverse (CAP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Gold Hits $3,700 as Sprott’s Wong Says Dollar’s Store-of-Value Crown May Slip

Gold Hits $3,700 as Sprott’s Wong Says Dollar’s Store-of-Value Crown May Slip

The post Gold Hits $3,700 as Sprott’s Wong Says Dollar’s Store-of-Value Crown May Slip appeared on BitcoinEthereumNews.com. Gold is strutting its way into record territory, smashing through $3,700 an ounce Wednesday morning, as Sprott Asset Management strategist Paul Wong says the yellow metal may finally snatch the dollar’s most coveted role: store of value. Wong Warns: Fiscal Dominance Puts U.S. Dollar on Notice, Gold on Top Gold prices eased slightly to $3,678.9 […] Source: https://news.bitcoin.com/gold-hits-3700-as-sprotts-wong-says-dollars-store-of-value-crown-may-slip/
Share
BitcoinEthereumNews2025/09/18 00:33
Why Institutional Capital Chooses Gold Over Bitcoin Amid Yen Currency Crisis

Why Institutional Capital Chooses Gold Over Bitcoin Amid Yen Currency Crisis

TLDR: Yen’s managed devaluation artificially strengthens the dollar, creating headwinds for Bitcoin price action. Gold has surged 61.4% while Bitcoin stagnates
Share
Blockonomi2026/01/18 12:09
Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36