Notification
Mycryptopot
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • Nft
    • Solana
    • XRP
    • Tron
  • MarketCap
  • Market
  • Forex
  • Mining
  • Metaverse
  • Exchange
  • Regulations
  • Analysis
    • Crypto Bubbles
    • Multi Currency
    • Evaluation
Reading: Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Share
bitcoin
Bitcoin (BTC) $ 66,672.00
ethereum
Ethereum (ETH) $ 1,792.60
tether
Tether (USDT) $ 0.99936
bnb
BNB (BNB) $ 615.58
usd-coin
USDC (USDC) $ 0.999759
xrp
XRP (XRP) $ 1.24
binance-usd
BUSD (BUSD) $ 0.999745
dogecoin
Dogecoin (DOGE) $ 0.088409
cardano
Cardano (ADA) $ 0.179854
solana
Solana (SOL) $ 74.94
polkadot
Polkadot (DOT) $ 1.02
tron
TRON (TRX) $ 0.317575
MycryptopotMycryptopot
Search
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • Nft
    • Solana
    • XRP
    • Tron
  • MarketCap
  • Market
  • Forex
  • Mining
  • Metaverse
  • Exchange
  • Regulations
  • Analysis
    • Crypto Bubbles
    • Multi Currency
    • Evaluation
© 2024 All Rights reserved | Powered by Crypto My Crypto Pot
Mycryptopot > News > Crypto > Solana > Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Solana

Largest supply chain attack in history targets crypto users through compromised JavaScript packages

September 8, 2025 3 Min Read
Share
Largest supply chain attack in history targets crypto users through compromised JavaScript packages
mycryptopot

A brand new cyberattack is silently concentrating on crypto from customers throughout transactions amid an incident that safety researchers describe as the biggest provide chain assault in historical past.

BleepingComputer reported that hackers compromised NPM package deal maintainer accounts by way of phishing emails and injected malware that steals crypto.

The assault focused JavaScript builders with fraudulent emails showing to originate from “[email protected],” an impersonated area mimicking the official NPM registry.

The phishing messages warned maintainers that their accounts can be locked on Sept. 10, except they up to date their two-factor authentication credentials by way of a malicious hyperlink.

mycryptopot

Attackers efficiently compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries embrace basic growth instruments similar to “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting nearly all the JavaScript ecosystem.

Focusing on crypto

The malicious code operates as a browser-based interceptor, monitoring community visitors for crypto transactions throughout Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Money networks.

When customers provoke crypto transfers, the malware silently replaces vacation spot pockets addresses with attacker-controlled accounts earlier than transaction signing.

mycryptopot

Aikido Safety researcher Charlie Eriksen defined:

The Crypto Investor Blueprint: A 5-Day Course On Bagholding, Insider Entrance-Runs, and Lacking Alpha

Good 😎 Your first lesson is on the best way.

Please add [email protected] to your e-mail whitelist.

“What makes it harmful is that it operates at a number of layers: altering content material proven on web sites, tampering with API calls, and manipulating what customers’ apps consider they’re signing.”

Ledger CTO Charles Guillemet warned crypto customers concerning the ongoing menace, noting the JavaScript ecosystem could also be compromised given the huge obtain figures.

{Hardware} pockets customers retain safety in the event that they confirm transaction particulars earlier than signing, whereas software program pockets customers face a better danger. Guillemet suggested:

“For those who don’t use a {hardware} pockets, chorus from making any on-chain transactions for now.”

He additionally famous uncertainty about whether or not attackers can immediately extract seed phrases from software program wallets.

Refined concentrating on

The assault represents a complicated provide chain concentrating on the place criminals compromise trusted growth infrastructure to succeed in finish customers.

By infiltrating packages downloaded billions of instances weekly, attackers gained unprecedented entry to cryptocurrency purposes and pockets interfaces.

BleepingComputer recognized the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows related JavaScript library compromises all through 2025, together with the July assault on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten standard NPM libraries.

Talked about on this article
mycryptopot

You Might Also Like

The Curse Of Ethereum: First-Ever ETH Treasury Company Suffers Sharo 73% Crash – Details

US Government May Seize Venezuela’s Bitcoin & crypto Reserves

Bit Digital reports 14% revenue drop in Q1, driven by lower ETH staking rewards

Let’s Not Create $200 Trillion in Credit on Top of Bitcoin

How High Can XRP Rise In The Next Year?

TAGGED:BitcoinBitcoin CashCoinscryptoEthereumFeaturedHacksLitecoinSolanaSolana AnalysisSolana NewsTRON
Share This Article
Facebook Twitter Copy Link
Previous Article image Ripple’s Mysterious 250,000,000 XRP Transfer Explained by Fresh Data
Next Article image Illiquid Bitcoin supply climbs to 14.3M as holders tighten grip
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
mycryptopot

Popular News

Tangle Network Partners with Orochi Network to Advance Blockchain Capabilities
Tangle Network Partners with Orochi Network to Advance Blockchain Capabilities
SONEX launches on Soneium’s mainnet 
SONEX launches on Soneium’s mainnet 
Shiba Inu
Solana Unveils “Seeker” Phone: Will SOL Spike To $250 Now?
Shiba Inu
Cardano: Recent Poll Has ADA Beating Out Ethereum & Solana
image
can ETH break $1,780 after US-Iran risk rally?
Highlights From ABS2024 In Taipei: 13,245 Attendees Gather For Asia’s Premier Blockchain Summit
Highlights From ABS2024 In Taipei: 13,245 Attendees Gather For Asia’s Premier Blockchain Summit
- Advertisement -
mycryptopot

You Might Also Like

image
Ethereum

Ethereum Treasury Company Bitmine Continues to Grow Its ETH Reserves! Here’s the Latest Purchase Amount

June 13, 2026
image
Ethereum

ETH Holds $3.1K in Extreme Fear as Ethereum crypto news focuses on cautious accumulation

December 11, 2025
Bitcoin
Bitcoin

Bitcoin OTC Dominance Rises To 82% As Coinbase Leads CEX Flows – Details

April 12, 2026
image
Bitcoin

The Big Bull Michael Saylor is Back! A Huge Buy After a 32 Bitcoin Sell! Here’s How Much BTC He Holds!

June 8, 2026
Mycryptopot

"Welcome to MyCryptoPot, your go-to source for the latest insights and developments in the ever-evolving world of cryptocurrency.

Editor Choice

VitaminAi and XDB Chain Forge Strategic Alliance to Shape the Future of Brand Value in Web3
Ethereum Exchange Balances Drop To 9-Year Low – Time For A Major Price Move?
Can ETH Hold The Crucial $1,930 Lifeline?

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Facebook Twitter Telegram
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Reading: Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Share
© 2024 All Rights reserved | Powered by Crypto My Crypto Pot
Welcome Back!

Sign in to your account

Lost your password?