Notification
Mycryptopot
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • Nft
    • Solana
    • XRP
    • Tron
  • MarketCap
  • Market
  • Forex
  • Mining
  • Metaverse
  • Exchange
  • Regulations
  • Analysis
    • Crypto Bubbles
    • Multi Currency
    • Evaluation
Reading: Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Share
bitcoin
Bitcoin (BTC) $ 78,219.00
ethereum
Ethereum (ETH) $ 2,303.52
tether
Tether (USDT) $ 0.999791
bnb
BNB (BNB) $ 615.20
usd-coin
USDC (USDC) $ 0.99981
xrp
XRP (XRP) $ 1.39
binance-usd
BUSD (BUSD) $ 0.996942
dogecoin
Dogecoin (DOGE) $ 0.107917
cardano
Cardano (ADA) $ 0.248893
solana
Solana (SOL) $ 83.87
polkadot
Polkadot (DOT) $ 1.21
tron
TRON (TRX) $ 0.331366
MycryptopotMycryptopot
Search
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • Nft
    • Solana
    • XRP
    • Tron
  • MarketCap
  • Market
  • Forex
  • Mining
  • Metaverse
  • Exchange
  • Regulations
  • Analysis
    • Crypto Bubbles
    • Multi Currency
    • Evaluation
© 2024 All Rights reserved | Powered by Crypto My Crypto Pot
Mycryptopot > News > Crypto > Solana > Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Solana

Largest supply chain attack in history targets crypto users through compromised JavaScript packages

September 8, 2025 3 Min Read
Share
Largest supply chain attack in history targets crypto users through compromised JavaScript packages
mycryptopot

A brand new cyberattack is silently concentrating on crypto from customers throughout transactions amid an incident that safety researchers describe as the biggest provide chain assault in historical past.

BleepingComputer reported that hackers compromised NPM package deal maintainer accounts by way of phishing emails and injected malware that steals crypto.

The assault focused JavaScript builders with fraudulent emails showing to originate from “[email protected],” an impersonated area mimicking the official NPM registry.

The phishing messages warned maintainers that their accounts can be locked on Sept. 10, except they up to date their two-factor authentication credentials by way of a malicious hyperlink.

mycryptopot

Attackers efficiently compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries embrace basic growth instruments similar to “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting nearly all the JavaScript ecosystem.

Focusing on crypto

The malicious code operates as a browser-based interceptor, monitoring community visitors for crypto transactions throughout Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Money networks.

When customers provoke crypto transfers, the malware silently replaces vacation spot pockets addresses with attacker-controlled accounts earlier than transaction signing.

mycryptopot

Aikido Safety researcher Charlie Eriksen defined:

The Crypto Investor Blueprint: A 5-Day Course On Bagholding, Insider Entrance-Runs, and Lacking Alpha

Good 😎 Your first lesson is on the best way.

Please add [email protected] to your e-mail whitelist.

“What makes it harmful is that it operates at a number of layers: altering content material proven on web sites, tampering with API calls, and manipulating what customers’ apps consider they’re signing.”

Ledger CTO Charles Guillemet warned crypto customers concerning the ongoing menace, noting the JavaScript ecosystem could also be compromised given the huge obtain figures.

{Hardware} pockets customers retain safety in the event that they confirm transaction particulars earlier than signing, whereas software program pockets customers face a better danger. Guillemet suggested:

“For those who don’t use a {hardware} pockets, chorus from making any on-chain transactions for now.”

He additionally famous uncertainty about whether or not attackers can immediately extract seed phrases from software program wallets.

Refined concentrating on

The assault represents a complicated provide chain concentrating on the place criminals compromise trusted growth infrastructure to succeed in finish customers.

By infiltrating packages downloaded billions of instances weekly, attackers gained unprecedented entry to cryptocurrency purposes and pockets interfaces.

BleepingComputer recognized the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows related JavaScript library compromises all through 2025, together with the July assault on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten standard NPM libraries.

Talked about on this article
mycryptopot

You Might Also Like

Ethereum price slips below $3K as ETH ETFs see three-day outflows

Ethereum (ETH) Price Prediction for June 26

Bitcoin ETF “record outflows” are deceptive as crypto products absorbed $46.7 billion in 2025

Consensys-Linked Wallet Makes Strategic $49.6M ETH Acquisition via Galaxy Digital

Bitcoin Isn’t Dying, It’s Changing Hands, Analyst Says

TAGGED:BitcoinBitcoin CashCoinscryptoEthereumFeaturedHacksLitecoinSolanaSolana AnalysisSolana NewsTRON
Share This Article
Facebook Twitter Copy Link
Previous Article image Ripple’s Mysterious 250,000,000 XRP Transfer Explained by Fresh Data
Next Article image Illiquid Bitcoin supply climbs to 14.3M as holders tighten grip
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
mycryptopot

Popular News

Tangle Network Partners with Orochi Network to Advance Blockchain Capabilities
Tangle Network Partners with Orochi Network to Advance Blockchain Capabilities
SONEX launches on Soneium’s mainnet 
SONEX launches on Soneium’s mainnet 
Shiba Inu
Solana Unveils “Seeker” Phone: Will SOL Spike To $250 Now?
Shiba Inu
Cardano: Recent Poll Has ADA Beating Out Ethereum & Solana
image
Institutional demand to drive bitcoin market cap to $16 trillion by 2030: Ark Invest
Highlights From ABS2024 In Taipei: 13,245 Attendees Gather For Asia’s Premier Blockchain Summit
Highlights From ABS2024 In Taipei: 13,245 Attendees Gather For Asia’s Premier Blockchain Summit
- Advertisement -
mycryptopot

You Might Also Like

VeChain VET
Solana

Solana: AI Sets SOL Price For November 15

November 13, 2024
image
Market

Bitcoin and Ethereum’s Rise Also Reflected in ETFs! Record Inflows to ETFs!

October 12, 2025
Fidelity Allegedly Planning to File for Bitcoin ETF, Claims Source
Solana

$6 Trillion Asset Manager Fidelity to Launch Crypto Stablecoin

January 28, 2026
image
Bitcoin

Most Important Bitcoin Price Level to Watch Out For

August 4, 2025
Mycryptopot

"Welcome to MyCryptoPot, your go-to source for the latest insights and developments in the ever-evolving world of cryptocurrency.

Editor Choice

Coinbase CEO urges next SEC chief to apologize for crypto crackdown
Binance Futures Announces the Listing of a New Altcoin Trading Pair! Here Are the Details.
Tsar of cryptocurrencies seeks the end to a rule that suffocates the defici platforms

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Facebook Twitter Telegram
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Reading: Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Share
© 2024 All Rights reserved | Powered by Crypto My Crypto Pot
Welcome Back!

Sign in to your account

Lost your password?