The contaminated code has already been pulled into countless projects, potentially endangering millions of crypto wallets and decentralized applications that […] The post Hackers Just Turned JavaScript Into a Crypto Time Bomb appeared first on Coindoo.The contaminated code has already been pulled into countless projects, potentially endangering millions of crypto wallets and decentralized applications that […] The post Hackers Just Turned JavaScript Into a Crypto Time Bomb appeared first on Coindoo.

Hackers Just Turned JavaScript Into a Crypto Time Bomb

2025/09/09 06:38
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

The contaminated code has already been pulled into countless projects, potentially endangering millions of crypto wallets and decentralized applications that rely on these dependencies.

Instead of targeting a single blockchain or wallet, the malicious updates act like a universal parasite. They scan data flows for wallet addresses — from Bitcoin and Ethereum to Solana, Tron, and Litecoin — and quietly swap them out with attacker-controlled lookalikes. The goal: reroute transactions before users even realize what happened.

How the Breach Was Discovered

The first signs of trouble emerged when developers noticed failed builds tied to a strange update of error-ex. That release, version 1.3.3, contained scrambled code and an odd function named checkethereumw. Security analysts later confirmed it was designed to steal crypto data. Other widely used libraries, including color-convert and strip-ansi, were also compromised.

Ledger’s chief technology officer, Charles Guillemet, went public with warnings, calling attention to the scale of the incident. According to him, billions of downloads mean this isn’t an isolated event but a systemic threat. His advice was blunt: anyone relying solely on software wallets should stop transactions until the danger is contained, while hardware wallet users must double-check every signature.

READ MORE:

Vitalik Buterin Just Dropped a New Ethereum Proposal

The Bigger Picture

This breach isn’t happening in a vacuum. It lands as the blockchain sector faces a wave of security shocks, including a recent report that the Lubian mining pool lost more than 127,000 BTC in another exploit. The common thread is clear — attackers are shifting from direct protocol hacks to infiltrating the tools and libraries developers trust most.

While panic spread across developer communities, not every project has been caught in the blast radius. Solana’s leading DEX aggregator, Jupiter, said it had combed through its systems and confirmed it doesn’t rely on the infected versions. The team reassured users that both its web and mobile products remain secure.

What makes this attack chilling is its simplicity. By compromising just one NPM account, hackers gained a foothold into an ecosystem that powers everything from small web apps to critical blockchain infrastructure. For now, vigilance is the only defense — reviewing dependencies, halting unnecessary transfers, and waiting for the all-clear from security researchers.


This publication is sponsored. Coindoo does not endorse or assume responsibility for the content, accuracy, quality, advertising, products, or any other materials on this page. Readers are encouraged to conduct their own research before engaging in any cryptocurrency-related actions. Coindoo will not be liable, directly or indirectly, for any damages or losses resulting from the use of or reliance on any content, goods, or services mentioned. Always do your own research.

The post Hackers Just Turned JavaScript Into a Crypto Time Bomb appeared first on Coindoo.

시장 기회
Bombie 로고
Bombie 가격(BOMB)
$0.00001599
$0.00001599$0.00001599
0.00%
USD
Bombie (BOMB) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!