MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,716.00-0.16%
  • ethereumEthereum(ETH)$2,309.29-1.44%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.430.94%
  • binancecoinBNB(BNB)$634.29-0.22%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.59-0.14%
  • tronTRON(TRX)$0.328215-0.40%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.46%
  • dogecoinDogecoin(DOGE)$0.0970431.38%
Blockchain Security

Hackers Carry Out The Largest NPM Attack In History, But Stole Less Than $50

Last updated: September 10, 2025 5:30 am
Published: 8 months ago
Share

Hackers launched the largest NPM crypto attack in history and compromised 18 JavaScript packages with billions of downloads. However, they stole less than $50.

The largest NPM crypto attack in history has been confirmed this week. However, despite how large it was, its outcome was surprisingly small.

Despite affecting widely used JavaScript libraries downloaded billions of times, hackers were able to steal less than $50 worth of crypto.

Hackers gained access to the Node Package Manager (NPM) account of a well-known developer, Josh Junon, also known as “qix.” They used a phishing email that impersonated an official npmjs.com support address. The email urged Junon and other maintainers to update their two-factor authentication and threatened to lock accounts if they failed to comply.

Once Junon’s account was compromised, attackers injected malware into 18 of his NPM packages. These included widely used libraries like chalk, strip-ansi, and debug, which, when combined, see more than 2.6 billion downloads every week.

The malware worked as a crypto-clipper.

It simply monitored Ethereum, Bitcoin, Solana, Tron, Litecoin and Bitcoin Cash wallet addresses. When a transaction was initiated, it simply replaced the destination address with an attacker-controlled address.

According to blockchain security firm Security Alliance, the financial effect was minimal. The hacker(s)’ Ethereum address, identified as “0xFc4a48”, has received less than $50 in assets.

Initial reports showed only five cents stolen in Ether. Later, around $20 worth of a memecoin was added.

The wallet also received small amounts of tokens like Brett, Andy, Dork Lord, Ethervista and Gondola. This indicates that the attacker either failed to spread the malware widely enough or users quickly identified and blocked any suspicious transactions.

Even though losses were small, the event further pointed out the risks of supply chain attacks.

Developers who never directly installed the compromised packages may still have been exposed, because the libraries sit deep in dependency trees used by countless projects.

Ledger’s chief technology officer, Charles Guillemet, urged developers to be cautious and urged everyone to double-check wallet addresses during transactions. Crypto apps like Phantom Wallet and Uniswap also confirmed that they were not affected, while Ledger and MetaMask reassured users of their defenses.

DefiLlama founder 0xngmi noted that only projects updated after the hacker’s exploit was released could be at risk.

According to Aikido Security, the injected code hooked into JavaScript functions like fetch, XMLHttpRequest, and wallet APIs like window Ethereum and Solana connectors.

It intercepted crypto activity in the browser and manipulated wallet interactions, while rewriting the payment destinations.

This made the attack dangerous because it worked across multiple layers. It changed content displayed to users and tampered with API calls.

Still, the malware only affected users who installed the updated packages during the brief compromise window. This limited its reach compared to other large-scale hacks.

The incident further calls for the need for stronger security practices among developers. Two-factor authentication is important, but phishing emails that impersonate trusted services will always be effective.

For crypto users, the advice is simple. Always verify wallet addresses before sending funds. Use wallets with built-in security layers like MetaMask and Ledger, which can block known malicious scripts.

Security firms also recommend that developers pin dependency versions in their projects and use automated scanning tools to detect any unexpected changes in libraries.

Read more on Live Bitcoin News

This news is powered by Live Bitcoin News Live Bitcoin News

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

WOO X Hack Suspected, $12M+ Lost Across BTC, ETH, BNB, ARB
Hashex Audit Confirms MAGACOIN FINANCE Passed Security Review, Reddit Discussion Turns Constructive
MyGold Token Announces Global Presale Launch on GemPad, Targeting $300 Million With Gold-Backed Blockchain Innovation
Rosen Law Firm Encourages Balancer Investors to Inquire About Securities Class Action Investigation – BAL
2026 Cybersecurity Forecasts: Real AI Threats vs. Overhyped Risks

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Uranium market heats up on nuclear revival hopes
Next Article History is full of failed attempts to establish new currencies. So what makes crypto different?
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d