MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Hackers net roughly $503 in ‘failed’ NPM supply chain attack
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$67,043.00-1.23%
  • ethereumEthereum(ETH)$1,959.67-1.17%
  • tetherTether(USDT)$1.00-0.02%
  • rippleXRP(XRP)$1.36-2.30%
  • binancecoinBNB(BNB)$598.69-2.90%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$79.99-1.52%
  • tronTRON(TRX)$0.277179-0.36%
  • dogecoinDogecoin(DOGE)$0.093395-0.14%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.04-0.38%
Smart Contracts

Hackers net roughly $503 in ‘failed’ NPM supply chain attack

Last updated: September 9, 2025 5:05 pm
Published: 5 months ago
Share

Several web3 and DeFi platforms, including Uniswap and Aave, stated that they were unaffected.

Ledger’s chief technology officer said Tuesday that a widely watched supply-chain attack on the Node Package Manager ecosystem “fortunately failed,” with “almost no victims,” after a phishing campaign let attackers publish malicious updates to popular JavaScript packages before the compromise was detected and shut down.

Charles Guillemet, Ledger’s CTO, stated the incident began with emails from a spoofed NPM support domain that harvested developer credentials. This allowed hackers to push tainted package versions that hook web-crypto activity across Ethereum, Solana, and other chains by swapping destination addresses inside network responses.

He added that implementation mistakes caused CI/CD pipelines to crash, triggering rapid discovery and limiting the impact size. “The immediate danger may have passed, but the threat hasn’t,” Ledger’s CTO wrote on X, urging users to favor hardware wallets and clear signing protections. The attackers only netted about $503 in crypto, according to onchain analytics firm Arkham, which said the funds went to addresses cited by Guillemet in his initial alert.

The update follows Monday’s industry-wide, as reported by The Block. Security experts urged developers and users to pause onchain activity amid a massive NPM supply-chain event targeting web3 projects. By early Tuesday, multiple crypto teams, including Uniswap, Morpho, MetaMask, OKX Wallet, Sui, Aave, Trezor, and Lido, reported they were not affected.

Security collective SEAL Org called the outcome “lucky,” noting a compromised account with packages downloaded “billions” of times weekly could have yielded “untold riches” had the payload been stealthier.

While the take was minimal this time, industry veterans like Guillemet warned that software supply chain compromises remain a powerful malware vector and are becoming increasingly targeted. The Block recently covered investigative work showing attackers embedding command-and-control instructions behind Ethereum smart contracts to steer NPM-distributed malware, a sign that adversaries are blending onchain and open-source tactics to dodge detection.

Read more on The Block

This news is powered by The Block The Block

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Stripe and Paradigm Reportedly Working on a New Blockchain Called Tempo
1inch launches Aqua: The first shared liquidity protocol, now available for developers
Crypto Market Shock: While Bitcoin Holds at $70K, Lyno AI Presale Quietly Builds the Next $1B AI Token
Bitcoin Price Forecast: Why A Move To $100K Makes Sense, Remittix Presale Nears 95% Sold Out – Cryptopolitan
DOGE seamlessly integrated, opening a new era of cross-chain mining

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Chainlink and Cronos Dip While BlockchainFX Hits $7 Million – Why Analysts Are Calling It The Top Crypto Presale Of The Year!
Next Article 10 Reasons LYNO Could Be the Best Presale Buy of 2025
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d