Notification
Mycryptopot
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • Nft
    • Solana
    • XRP
    • Tron
  • MarketCap
  • Market
  • Forex
  • Mining
  • Metaverse
  • Exchange
  • Regulations
  • Analysis
    • Crypto Bubbles
    • Multi Currency
    • Evaluation
Reading: Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Share
bitcoin
Bitcoin (BTC) $ 73,079.00
ethereum
Ethereum (ETH) $ 2,241.38
tether
Tether (USDT) $ 0.999985
bnb
BNB (BNB) $ 675.08
usd-coin
USDC (USDC) $ 0.999956
xrp
XRP (XRP) $ 1.47
binance-usd
BUSD (BUSD) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.100186
cardano
Cardano (ADA) $ 0.28493
solana
Solana (SOL) $ 92.81
polkadot
Polkadot (DOT) $ 1.61
tron
TRON (TRX) $ 0.296798
MycryptopotMycryptopot
Search
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • Nft
    • Solana
    • XRP
    • Tron
  • MarketCap
  • Market
  • Forex
  • Mining
  • Metaverse
  • Exchange
  • Regulations
  • Analysis
    • Crypto Bubbles
    • Multi Currency
    • Evaluation
© 2024 All Rights reserved | Powered by Crypto My Crypto Pot
Mycryptopot > News > Crypto > Solana > Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Solana

Largest supply chain attack in history targets crypto users through compromised JavaScript packages

September 8, 2025 3 Min Read
Share
Largest supply chain attack in history targets crypto users through compromised JavaScript packages
mycryptopot

A brand new cyberattack is silently concentrating on crypto from customers throughout transactions amid an incident that safety researchers describe as the biggest provide chain assault in historical past.

BleepingComputer reported that hackers compromised NPM package deal maintainer accounts by way of phishing emails and injected malware that steals crypto.

The assault focused JavaScript builders with fraudulent emails showing to originate from “[email protected],” an impersonated area mimicking the official NPM registry.

The phishing messages warned maintainers that their accounts can be locked on Sept. 10, except they up to date their two-factor authentication credentials by way of a malicious hyperlink.

mycryptopot

Attackers efficiently compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries embrace basic growth instruments similar to “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting nearly all the JavaScript ecosystem.

Focusing on crypto

The malicious code operates as a browser-based interceptor, monitoring community visitors for crypto transactions throughout Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Money networks.

When customers provoke crypto transfers, the malware silently replaces vacation spot pockets addresses with attacker-controlled accounts earlier than transaction signing.

mycryptopot

Aikido Safety researcher Charlie Eriksen defined:

The Crypto Investor Blueprint: A 5-Day Course On Bagholding, Insider Entrance-Runs, and Lacking Alpha

Good 😎 Your first lesson is on the best way.

Please add [email protected] to your e-mail whitelist.

“What makes it harmful is that it operates at a number of layers: altering content material proven on web sites, tampering with API calls, and manipulating what customers’ apps consider they’re signing.”

Ledger CTO Charles Guillemet warned crypto customers concerning the ongoing menace, noting the JavaScript ecosystem could also be compromised given the huge obtain figures.

{Hardware} pockets customers retain safety in the event that they confirm transaction particulars earlier than signing, whereas software program pockets customers face a better danger. Guillemet suggested:

“For those who don’t use a {hardware} pockets, chorus from making any on-chain transactions for now.”

He additionally famous uncertainty about whether or not attackers can immediately extract seed phrases from software program wallets.

Refined concentrating on

The assault represents a complicated provide chain concentrating on the place criminals compromise trusted growth infrastructure to succeed in finish customers.

By infiltrating packages downloaded billions of instances weekly, attackers gained unprecedented entry to cryptocurrency purposes and pockets interfaces.

BleepingComputer recognized the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows related JavaScript library compromises all through 2025, together with the July assault on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten standard NPM libraries.

Talked about on this article
mycryptopot

You Might Also Like

Vitalik Buterin Outlines Ethereum’s AI Vision As Alternative To The Race For AGI

Figment expands institutional staking into Latin America

Twenty One Capital rises to 3rd largest Bitcoin holder following 5,800 BTC boost from Tether

Sidelined or Setup? Bitcoin’s Price Stalls, Traders Brace for Breakout

Central Bank of Brazil Dismisses Strategic Bitcoin Reserve Implementation

TAGGED:BitcoinBitcoin CashCoinscryptoEthereumFeaturedHacksLitecoinSolanaSolana AnalysisSolana NewsTRON
Share This Article
Facebook Twitter Copy Link
Previous Article image Ripple’s Mysterious 250,000,000 XRP Transfer Explained by Fresh Data
Next Article image Illiquid Bitcoin supply climbs to 14.3M as holders tighten grip
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
mycryptopot

Popular News

Tangle Network Partners with Orochi Network to Advance Blockchain Capabilities
Tangle Network Partners with Orochi Network to Advance Blockchain Capabilities
SONEX launches on Soneium’s mainnet 
SONEX launches on Soneium’s mainnet 
image
What Moves XRP Price? Ripple CTO Emeritus Breaks Down 3 Factors
Shiba Inu
Solana Unveils “Seeker” Phone: Will SOL Spike To $250 Now?
Shiba Inu
Cardano: Recent Poll Has ADA Beating Out Ethereum & Solana
Highlights From ABS2024 In Taipei: 13,245 Attendees Gather For Asia’s Premier Blockchain Summit
Highlights From ABS2024 In Taipei: 13,245 Attendees Gather For Asia’s Premier Blockchain Summit
- Advertisement -
mycryptopot

You Might Also Like

Bitmine Keeps Buying Ethereum Despite Market Drop: 21,054 ETH Arrive In New Wallet
Ethereum

Bitmine Keeps Buying Ethereum Despite Market Drop: 21,054 ETH Arrive In New Wallet

November 20, 2025
Will Ethereum Price Hit $4,000 as Open Interest Reaches $33 Billion?
Ethereum

Will Ethereum Price Hit $4,000 as Open Interest Reaches $33 Billion?

May 17, 2025
Bitcoin Bounces After War-Driven Dip, $98.2K Emerges as Key Level to Maintain Bullish Momentum
Bitcoin

Bitcoin Bounces After War-Driven Dip, $98.2K Emerges as Key Level to Maintain Bullish Momentum

June 26, 2025
Institutional investors now hold 20% of US-traded spot Bitcoin ETFs
Bitcoin

Institutional investors now hold 20% of US-traded spot Bitcoin ETFs

October 23, 2024
Mycryptopot

"Welcome to MyCryptoPot, your go-to source for the latest insights and developments in the ever-evolving world of cryptocurrency.

Editor Choice

Here Are The Top 10 NFT Projects By Activity In the Last 7 Days
Ripple (XRP) Rallies 21% In 1 Week: $3.50 May Be Closer Than You Think
Bitcoin is swallowing billions in ETF cash again, but a specific “market wrapper” is killing the price breakout

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Facebook Twitter Telegram
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Reading: Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Share
© 2024 All Rights reserved | Powered by Crypto My Crypto Pot
Welcome Back!

Sign in to your account

Lost your password?