A malicious npm package compromise threatens JavaScript projects and crypto wallets. Here’s how it works and how to stay safe.A malicious npm package compromise threatens JavaScript projects and crypto wallets. Here’s how it works and how to stay safe.

Breaking News: Crypto Funds at Risk from Massive Supply Chain Attack

2025/09/09 05:50
2 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Crypto Hack: What Happened?

A widely used npm package, error-ex, was tampered with in its 1.3.3 release. Hidden inside was obfuscated code that activates two dangerous attack modes:

  • Clipboard Hijacking: When you paste a wallet address, the malware silently swaps it with the attacker’s lookalike address.
  • Transaction Interception: If you use a browser wallet, the code can intercept transaction calls and change the recipient’s address before you even see the confirmation screen.

This makes it nearly impossible to notice unless you carefully check every single character of the address you’re sending to.

Who’s at Risk from this Crypto Hack?

  1. Developers: Any project pulling dependencies without strict version pinning may have installed the infected version. This could affect CI pipelines, production builds, and apps that rely on JavaScript.
  2. Crypto Users: The malware targets major assets including $BTC, $ETH, $SOL, $TRX, $LTC, and $BCH. Both clipboard users and browser wallets are at risk.
  3. Platforms: Even centralized apps integrating npm libraries may have unknowingly included the malicious code.

Which Companies were Affected?

Already, SwissBorg confirmed a breach linked to a compromised partner API. Roughly 192.6K SOL (~$41.5M) was drained in the attack. While the SwissBorg app itself remains secure, its SOL Earn Program was hit, affecting <1% of users. The platform has promised recovery measures, including treasury funds and support from white-hat hackers.

How to Protect Yourself

Here’s what you need to do right now:

For Wallet Users

✅ Always verify every transaction — check the full recipient address before signing.
✅ Use a hardware wallet with clear signing enabled.
✅ Avoid unnecessary browser wallet extensions.
✅ If something feels off (unexpected signing requests), close the tab immediately.

For Developers

⚙️ Switch CI builds from npm install to npm ci to lock dependencies.
⚙️ Run npm ls error-ex to detect infected installs.
⚙️ Pin safe versions (error-ex@1.3.2) and regenerate lockfiles.
⚙️ Add dependency scanners like Snyk or Dependabot.
⚙️ Treat package-lock changes with the same scrutiny as code reviews.

Outlook

This incident highlights the fragility of supply chains in Web3 and beyond. A small package compromise can cascade into billions of downloads, hitting both developers and crypto holders worldwide. The immediate danger lies in address-swapping attacks, but the broader concern is how deep this could spread into financial infrastructure.

For now: check before you sign, pin your dependencies, and don’t take security shortcuts.

Market Opportunity
Safe Token Logo
Safe Token Price(SAFE)
$0.1033
$0.1033$0.1033
-0.09%
USD
Safe Token (SAFE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Aave: Will launch Aave Shield feature, which will by default block redemptions where the price affects the transaction by more than 25%.

Aave: Will launch Aave Shield feature, which will by default block redemptions where the price affects the transaction by more than 25%.

PANews reported on March 15th that a user who exchanged $50 million worth of USDT for AAVE through the Aave interface on March 12th failed to notice slippage warnings
Share
PANews2026/03/15 09:47
Iranian official: Ukraine has become a legitimate target for Iranian strikes

Iranian official: Ukraine has become a legitimate target for Iranian strikes

PANews reported on March 15 that, according to Xinhua News Agency, Ibrahim Aziz, chairman of the Iranian Parliament's National Security and Foreign Policy Committee
Share
PANews2026/03/15 10:46
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27