DeFi Daily News
Tuesday, November 18, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home Cryptocurrency Altcoins

rewrite this title Phishing, Bugs, and Billions at Stake: Lessons From NPM Crypto Exploit Near-Miss

Jared Kirui by Jared Kirui
September 9, 2025
in Altcoins
0 0
0
rewrite this title Phishing, Bugs, and Billions at Stake: Lessons From NPM Crypto Exploit Near-Miss
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

A failed attack on popular Node Package Manager (NPM)
libraries sent shockwaves through the crypto world on Monday.

Hackers targeted major packages to hijack
cryptocurrency transactions across multiple blockchains, but due to coding
errors, the breach caused minimal loss.

Still, experts warn that the incident highlights ongoing
risks for software wallets, exchanges, and any platform that automatically
updates code libraries.

NPM Attack Hits Popular Libraries

The attack reportedly started with a phishing email
sent from a fake NPM support domain, which allowed hackers to access developer accounts. Malicious updates were then pushed to libraries, including chalk, debug, and strip-ansi.

The injected code attempted to intercept wallet
addresses on chains like Bitcoin, Ethereum
Ethereum

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,
Read this Term
, Solana, Tron, and Litecoin.

Charles Guillemet, Ledger’s CTO, commented on X: “The
attack fortunately failed, with almost no victims. It began with a phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term

email from a fake npm support domain that stole credentials and gave attackers
access to publish malicious package updates.”

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,… https://t.co/Ud1SBSJ52v pic.twitter.com/lOik6k7Dkp

— Charles Guillemet (@P3b7_) September 9, 2025

According to Guillemet, the injected code targeted web
crypto activity, affecting Ethereum, Solana, and other blockchains, hijacking
transactions and replacing wallet addresses directly in network responses.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

“If your funds sit in a software wallet or on an
exchange, you’re one code execution away from losing everything. Supply-chain
compromises remain a powerful malware delivery vector, and we’re also seeing
more targeted attacks emerge,” he said.

Understanding the Threat

Anatoly Makosov, CTO of The Open Network (TON), also addressed the matter by explaining the mechanics of the attack on X and that only 18 specific package versions were compromised.

Makosov said developers who deployed builds shortly
after the malicious updates, or who rely on auto-updating libraries, were most
exposed. “Developers of multi-chain products should check their code,
especially if they have released something today,” he warned.

⚠️ Attack on popular NPM packages — technical details

A few hours ago, hackers gained access to some NPM accounts and published infected versions of popular libraries.

Many web products use these packages.

Although TON products do not appear to be at risk, developers of…

— Anatoly Makosov (@anatoly_makosov) September 8, 2025

Makosov emphasized that all earlier and newer versions
of the allegedly attacked packages are considered safe. Fixes have been
published, and developers are urged to reinstall clean code and rebuild their
applications.

Minimal Impact, Major Lesson

Despite the sophisticated attempt, the financial
impact was limited. Guillemet credited early detection to errors in the
attackers’ code that caused CI/CD pipeline crashes.

“Hardware wallets are built to withstand these
threats,” Guillemet said. Ledger devices include Clear Signing, letting users
verify transactions on a secure screen, and Transaction Check, which warns of
suspicious activity. “Your private keys and recovery phrase remain safe.
The immediate danger may have passed, but the threat hasn’t. Stay safe,” he
added.

Makosov and Guillemet both emphasized that vigilance
is crucial. Developers should lock dependencies to safe versions and avoid
dynamic updates, while users should avoid blind signing and always verify
wallet addresses.

Meanwhile, crypto wallet provider Ledger has assured
its users that its systems remain safe.

Ledger devices are not and have not been at risk during an ecosystem-wide software supply chain attack that was discovered.

Ledger devices are built specifically to protect users against attacks like these.

Only Ledger devices have secure screens, powered by the Secure Element… https://t.co/cJO2w0dpmU

— Ledger (@Ledger) September 8, 2025

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these,” the company mentioned.

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these.”

Developers have now been urged to examine their
projects’ package files for affected versions and update or rebuild with secure
releases. Users, meanwhile, should avoid blind signing and always verify wallet
addresses before confirming transactions.

A failed attack on popular Node Package Manager (NPM)
libraries sent shockwaves through the crypto world on Monday.

Hackers targeted major packages to hijack
cryptocurrency transactions across multiple blockchains, but due to coding
errors, the breach caused minimal loss.

Still, experts warn that the incident highlights ongoing
risks for software wallets, exchanges, and any platform that automatically
updates code libraries.

NPM Attack Hits Popular Libraries

The attack reportedly started with a phishing email
sent from a fake NPM support domain, which allowed hackers to access developer accounts. Malicious updates were then pushed to libraries, including chalk, debug, and strip-ansi.

The injected code attempted to intercept wallet
addresses on chains like Bitcoin, Ethereum
Ethereum

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,

Ethereum is an open source, blockchain-based distributed computing platform and operating system featuring smart contract functionality. Created in 2014, Ethereum now stands as the second largest cryptocurrency by market cap at the time of writing.As a decentralized cryptocurrency network and software platform, Ethereum represents the most prominent altcoin. Ethereum also enables the creation Distributed Applications, or dapps. Understanding EthereumEthereum boasts its own programming language,
Read this Term
, Solana, Tron, and Litecoin.

Charles Guillemet, Ledger’s CTO, commented on X: “The
attack fortunately failed, with almost no victims. It began with a phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term

email from a fake npm support domain that stole credentials and gave attackers
access to publish malicious package updates.”

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,… https://t.co/Ud1SBSJ52v pic.twitter.com/lOik6k7Dkp

— Charles Guillemet (@P3b7_) September 9, 2025

According to Guillemet, the injected code targeted web
crypto activity, affecting Ethereum, Solana, and other blockchains, hijacking
transactions and replacing wallet addresses directly in network responses.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

“If your funds sit in a software wallet or on an
exchange, you’re one code execution away from losing everything. Supply-chain
compromises remain a powerful malware delivery vector, and we’re also seeing
more targeted attacks emerge,” he said.

Understanding the Threat

Anatoly Makosov, CTO of The Open Network (TON), also addressed the matter by explaining the mechanics of the attack on X and that only 18 specific package versions were compromised.

Makosov said developers who deployed builds shortly
after the malicious updates, or who rely on auto-updating libraries, were most
exposed. “Developers of multi-chain products should check their code,
especially if they have released something today,” he warned.

⚠️ Attack on popular NPM packages — technical details

A few hours ago, hackers gained access to some NPM accounts and published infected versions of popular libraries.

Many web products use these packages.

Although TON products do not appear to be at risk, developers of…

— Anatoly Makosov (@anatoly_makosov) September 8, 2025

Makosov emphasized that all earlier and newer versions
of the allegedly attacked packages are considered safe. Fixes have been
published, and developers are urged to reinstall clean code and rebuild their
applications.

Minimal Impact, Major Lesson

Despite the sophisticated attempt, the financial
impact was limited. Guillemet credited early detection to errors in the
attackers’ code that caused CI/CD pipeline crashes.

“Hardware wallets are built to withstand these
threats,” Guillemet said. Ledger devices include Clear Signing, letting users
verify transactions on a secure screen, and Transaction Check, which warns of
suspicious activity. “Your private keys and recovery phrase remain safe.
The immediate danger may have passed, but the threat hasn’t. Stay safe,” he
added.

Makosov and Guillemet both emphasized that vigilance
is crucial. Developers should lock dependencies to safe versions and avoid
dynamic updates, while users should avoid blind signing and always verify
wallet addresses.

Meanwhile, crypto wallet provider Ledger has assured
its users that its systems remain safe.

Ledger devices are not and have not been at risk during an ecosystem-wide software supply chain attack that was discovered.

Ledger devices are built specifically to protect users against attacks like these.

Only Ledger devices have secure screens, powered by the Secure Element… https://t.co/cJO2w0dpmU

— Ledger (@Ledger) September 8, 2025

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these,” the company mentioned.

“Ledger devices are not and have not been at risk
during an ecosystem-wide software supply chain attack that was discovered.
Ledger devices are built specifically to protect users against attacks like
these.”

Developers have now been urged to examine their
projects’ package files for affected versions and update or rebuild with secure
releases. Users, meanwhile, should avoid blind signing and always verify wallet
addresses before confirming transactions.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website [http://defi-daily.com] and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: BillionsBugsCryptoExploitLessonsNearMissNPMPhishingrewritestaketitle
ShareTweetShare
Previous Post

rewrite this title KuCoin Pay Introduces On-Chain Payment Solution For Merchants And Consumers, Expanding Access To Crypto Payments

Next Post

rewrite this title Glassnode: Market Stabilizes Above Short-Term Holder Levels As Momentum And Profitability Improve Amid Cautious Sentiment

Next Post
rewrite this title Glassnode: Market Stabilizes Above Short-Term Holder Levels As Momentum And Profitability Improve Amid Cautious Sentiment

rewrite this title Glassnode: Market Stabilizes Above Short-Term Holder Levels As Momentum And Profitability Improve Amid Cautious Sentiment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Ripple News: First U.S. Spot XRP ETF Surpasses 0 Million in Assets

rewrite this title Ripple News: First U.S. Spot XRP ETF Surpasses $100 Million in Assets

October 26, 2025
rewrite this title and make it good for SEO MEXC Vs KuCoin 2025: Which Exchange Is Better?

rewrite this title and make it good for SEO MEXC Vs KuCoin 2025: Which Exchange Is Better?

October 26, 2025
rewrite this title Soft Washed Pleated Comforter Set from .99 at Kohl’s!

rewrite this title Soft Washed Pleated Comforter Set from $19.99 at Kohl’s!

November 15, 2024
rewrite this title with good SEO Arthur Hayes Claims Bull Market Still In Play: Monetary Policy

rewrite this title with good SEO Arthur Hayes Claims Bull Market Still In Play: Monetary Policy

November 5, 2025
Stock market today: S&P 500 set to build on record high as Powell kicks off semiannual testimony

Stock market today: S&P 500 set to build on record high as Powell kicks off semiannual testimony

July 9, 2024
rewrite this title and make it good for SEO”Stop taking actions that harm America”: US Commerce Secretary sends stern message to India

rewrite this title and make it good for SEO”Stop taking actions that harm America”: US Commerce Secretary sends stern message to India

September 28, 2025
rewrite this title Best Sportsbook Promos in the US – Best Bonuses & Bonus Bets 2025

rewrite this title Best Sportsbook Promos in the US – Best Bonuses & Bonus Bets 2025

November 18, 2025
Crypto is dead?

Crypto is dead?

November 18, 2025
rewrite this title Morning Minute: Aave Takes Aim at Banks, Fintechs with New Aave App – Decrypt

rewrite this title Morning Minute: Aave Takes Aim at Banks, Fintechs with New Aave App – Decrypt

November 18, 2025
rewrite this title Global Launch Watch: November 2025 | Metaverse Planet

rewrite this title Global Launch Watch: November 2025 | Metaverse Planet

November 18, 2025
rewrite this title Teen Wolf’s Tyler Posey to direct serial killer thriller Sober House

rewrite this title Teen Wolf’s Tyler Posey to direct serial killer thriller Sober House

November 18, 2025
rewrite this title Dogecoin Breakdown Or Bottom? On-Chain Risk Hits Extreme Value Zone

rewrite this title Dogecoin Breakdown Or Bottom? On-Chain Risk Hits Extreme Value Zone

November 18, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.