The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the… The post NPM Hack Shows Supply Chain Threats Still Endanger Crypto appeared on BitcoinEthereumNews.com. A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets. Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.   If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector.  Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added.  Largest NPM attack stole only $50 in crypto  The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain.  Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more.  The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin.  Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack TON CTO breaks down NPM attack Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published.  Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions. This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the…

NPM Hack Shows Supply Chain Threats Still Endanger Crypto

2025/09/10 10:36
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

A recent Node Package Manager (NPM) attack stole just $50 worth of crypto, but industry experts say the incident highlights ongoing vulnerabilities for exchanges and software wallets.

Charles Guillemet, the chief technology officer of hardware wallet company Ledger, said in a Tuesday X post that the attempted exploit was a “clear reminder” that software wallets and exchanges remain exposed to risks.  

If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything,” he said, adding that supply-chain compromises remain a powerful malware delivery vector. 

Guillemet took the opportunity to advocate for hardware wallets, saying that features like clear signing and transaction checks would help users withstand such threats. “The immediate danger may have passed, but the threat hasn’t. Stay safe,” he added. 

Largest NPM attack stole only $50 in crypto 

The attack unfolded after hackers acquired credentials using a phishing email sent from a fake NPM support domain. 

Using their newly acquired access to developer accounts, the attackers pushed malicious updates to popular libraries. This included chalk, debug strip-ansi and more. 

The code they injected attempted to hijack transactions by intercepting wallet addresses and replacing them in network responses across several blockchains, including Bitcoin, Ethereum, Solana, Tron and Litecoin. 

Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack

TON CTO breaks down NPM attack

Anatoly Makosov, the chief technology officer of The Open Network (TON), said that only specific versions of 18 packages were compromised and that rollbacks were already published. 

Breaking down the mechanics of the attack, Makosov said compromised packages functioned as crypto clippers, which silently spoofed wallet addresses in products that relied on the infected versions.

This means web apps interacting with the aforementioned chains risked having their transactions intercepted and redirected without the knowledge of the users. 

He said that developers who pushed their builds within hours of the malicious updates and apps that auto-update their code libraries instead of freezing them to a safe version were the most exposed. 

Makosov shared a checklist on how developers can check if their apps were compromised. The main sign is whether the code is using one of 18 versions of popular libraries like ansi-styles, chalk or debug. He said if a project relies on these versions, it’s likely compromised. 

He said the fix is to switch back to safe versions, reinstall clean code and rebuild applications. He added that new and updated releases are already available and urged developers to act quickly to clear out the malware before it can affect their users. 

Magazine: BTS Jungkook’s hacker, Ripple backs Singapore payments firm: Asia Express

Source: https://cointelegraph.com/news/failed-npm-exploit-crypto-security-threat?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

시장 기회
스레숄드 로고
스레숄드 가격(T)
$0.006263
$0.006263$0.006263
+1.06%
USD
스레숄드 (T) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!