MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: How to stay safe if you’re using MetaMask, Phantom, Trust or any crypto wallet from NPM attack
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,678.00-0.62%
  • ethereumEthereum(ETH)$2,309.47-1.49%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.430.80%
  • binancecoinBNB(BNB)$635.54-0.12%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.34-0.68%
  • tronTRON(TRX)$0.327732-0.18%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.46%
  • dogecoinDogecoin(DOGE)$0.0975121.53%
Ethereum

How to stay safe if you’re using MetaMask, Phantom, Trust or any crypto wallet from NPM attack

Last updated: September 9, 2025 4:15 am
Published: 8 months ago
Share

A new cyberattack has put millions of crypto users on alert after hackers slipped malicious code into NPM, the software registry that powers thousands of apps and websites, including many tied to crypto wallets.

For non-developers, NPM (Node Package Manager) is like a giant library of free building blocks that software developers use to create apps. Every time you interact with a wallet extension like MetaMask or a DeFi dashboard, chances are some part of its code comes from NPM.

The problem is, if attackers sneak malware into one of those building blocks, it can spread to thousands of apps without users realizing. With more than 2 billion downloads every week, NPM is the plumbing of the internet, and a prime target.

Developers first noticed something was wrong when code builds started failing. Researcher StarPlatinum explained:

“Developers first noticed strange build errors like fetch is not defined. When they inspected the code, they found heavy obfuscation hiding functions like checkethereumw. A clear sign this was targeting crypto.”

Once inside, the malware had two tricks. As Minal Thukral detailed:

“The malware uses two sophisticated methods:

– Clipboard Hijacking: When you paste a wallet address, it stealthily swaps it with an attacker’s look-alike, making it extremely hard to spot the difference.

– Transaction Interception: It directly hooks into your wallet’s functions. When you go to sign a transaction, it changes the recipient’s address in the background before the confirmation prompt even appears.”

You could think you’re sending coins to a friend, but the malware might quietly reroute them to a hacker.

So far, the attacker’s Ethereum wallet and several backups have been identified, and no stolen funds have been moved. But the fact that the code ran in apps with billions of downloads has shaken trust.

sol.engineer summed it up:

“This code runs behind the scenes in apps with billions of downloads each week. Even big companies rely on it. Which means: any Solana platform, any wallet and more could be affected.”

The first step is slowing down. Many crypto users only check the first and last few digits of wallet addresses when sending money but that’s exactly what attackers exploit.

As sol.engineer warned:

“Double-check every address before sending, slow down & verify every single character (NOT just first/last 4).”

Read more on Yahoo! Finance

This news is powered by Yahoo! Finance Yahoo! Finance

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Best Presales in September 2025 is Led by BullZilla, As Litecoin, and Polkadot Sparks Hype – Tekedia
2026 Market Update: Apeing Moves to the Front of Best New Meme Coins as BONK Stalls and FLOKI Consolidates – The Bit Journal
7 Best Cryptos to Watch in 2025: Top Picks Fueling the Next Meme Coin Boom – Crypto Economy
Is the Bull Run Back? Bitcoin Soars on a Wave of Macro Signals – BeInCrypto
Include Bitcoin in Tax Return, Here’s Why

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Ethereum L2 MegaETH introduces yield-bearing stablecoin to fund protocol
Next Article Melania Coin Gains, Snek Spikes 25% – But Is MoonBull the Best New Upcoming Crypto to Watch Right Now? – The Bit Journal
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d