• Crypto Market
  • Crypto List
  • Converter
The cryptonews hub
  • Currency Prices
  • Top Gainers
  • Top Losers
  • Trending News
  • Crypto News
    • Bitcoin
    • Ethereum
    • NFT
    • Tech
  • Blockchain
  • Market
  • Crypto Events
Reading: Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Share
The cryptonews hubThe cryptonews hub
Font ResizerAa
  • Trending News
  • Crypto News
  • Blockchain
  • Market
  • Crypto Events
  • Trending News
  • Crypto News
    • Bitcoin
    • NFT
    • Ethereum
    • Tech
  • Blockchain
  • Market
  • Quick Links
    • Crypto Converter
    • Crypto List
    • Crypto Market
    • Currency Prices
    • Crypto Events
    • Exchange
    • Top Gainers
    • Top Losers
Follow US

© 2026 The Crypto News Hub. Powered by Pantrade Blockchain

The cryptonews hub > Blog > Trending News > Largest supply chain attack in history targets crypto users through compromised JavaScript packages
Trending News

Largest supply chain attack in history targets crypto users through compromised JavaScript packages

Crypto Team
Last updated: September 9, 2025 4:46 am
Crypto Team
Published: September 9, 2025
Share
wp header logo 788 Largest supply chain attack in history targets crypto users through compromised JavaScript packages

A new cyberattack is silently targeting crypto from users during transactions amid an incident that security researchers describe as the largest supply chain attack in history.

BleepingComputer reported that hackers compromised NPM package maintainer accounts through phishing emails and injected malware that steals crypto.

- Advertisement -

The attack targeted JavaScript developers with fraudulent emails appearing to originate from “support@npmjs.help,” an impersonated domain mimicking the legitimate NPM registry.

The phishing messages warned maintainers that their accounts would be locked on Sept. 10, unless they updated their two-factor authentication credentials through a malicious link.

Attackers successfully compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries include fundamental development tools such as “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting virtually the entire JavaScript ecosystem.

When users initiate crypto transfers, the malware silently replaces destination wallet addresses with attacker-controlled accounts before transaction signing.

Aikido Security researcher Charlie Eriksen explained:

“What makes it dangerous is that it operates at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

Hardware wallet users retain protection if they verify transaction details before signing, while software wallet users face a higher risk. Guillemet advised:

“If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.”

He also noted uncertainty about whether attackers can directly extract seed phrases from software wallets.

The attack represents a sophisticated supply chain targeting where criminals compromise trusted development infrastructure to reach end users.

By infiltrating packages downloaded billions of times weekly, attackers gained unprecedented access to cryptocurrency applications and wallet interfaces.

BleepingComputer identified the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows similar JavaScript library compromises throughout 2025, including the July attack on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten popular NPM libraries.

source

Is a Crypto Bull Run on the Horizon? Market Cap Shows Upward Trend
Ton Foundation clarifies misleading announcement regarding UAE golden visa
Tether’s market share dips below 60% for first time since 2023
Leading Crypto Presales: Focus on BlockDAG, Pepe Unchained, FreeDum Fighters, and the Best Wallet Token
SEC Forms Task Force to Establish Clearer Crypto Regulations
Share This Article
Facebook Email Copy Link Print
Share
Previous Article wp header logo 787 Here’s why Ethereum price is preparing a monster move Here’s why Ethereum price is preparing a monster move
Next Article wp header logo 789 El Salvador’s Bitcoin Journey Hits 4-Year Mark, Results Still Divisive El Salvador’s Bitcoin Journey Hits 4-Year Mark, Results Still Divisive
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Follow US

Find US on Socials
FacebookLike
XFollow
InstagramFollow
Trending News
19 KinetFlow Launch Boosts Conflux Cross-Chain Capabilities
KinetFlow Launch Boosts Conflux Cross-Chain Capabilities
wp header logo 1923 How M2 money supply and the dollar REALLY move Bitcoin price – The truth influencers aren’t telling you
How M2 money supply and the dollar REALLY move Bitcoin price – The truth influencers aren’t telling you
wp header logo 1922 This $4.3M crypto home invasion shows how a single data leak can put anyone’s wallet — and safety — at risk
This $4.3M crypto home invasion shows how a single data leak can put anyone’s wallet — and safety — at risk
wp header logo 1918 Japan’s 20% crypto tax sets a new bar in Asia, pressuring Singapore and Hong Kong as retail costs fall
Japan’s 20% crypto tax sets a new bar in Asia, pressuring Singapore and Hong Kong as retail costs fall
wp header logo 1916 Did you know Bitcoin can stay alive without the internet?
Did you know Bitcoin can stay alive without the internet?
The cryptonews hub

The Cryptonews Hub brings breaking news on Bitcoin, Ethereum, Ripple, NFTs, DeFi, and blockchain. Get real-time prices, expert analysis, and earn free Bitcoin. Follow for top crypto updates!

Top Insight

Snoop Dogg NFT Collection Sells Out in 30 Minutes
December 31, 2025
Ethereum Quietly Sets Record Smart Contract Deployments
December 31, 2025

Top Categories

  • Trending News
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • Tech
  • Blockchain
  • Market

Quick Links

  • Crypto Market
  • Crypto List
  • Converter
  • Currency Price
  • Crypto Events
  • Top Exchanges
  • Top Gainers
  • Top Losers

© 2026 The Crypto News Hub. Powered by Pantrade Blockchain

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?