MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Largest npm attack in crypto history stole less than $50: SEAL
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$64,109.00-0.94%
  • ethereumEthereum(ETH)$1,860.52-0.01%
  • tetherTether(USDT)$1.000.03%
  • rippleXRP(XRP)$1.35-0.33%
  • binancecoinBNB(BNB)$585.64-1.90%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$78.960.61%
  • tronTRON(TRX)$0.2831610.69%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.25%
  • dogecoinDogecoin(DOGE)$0.091987-1.29%
Ethereum

Largest npm attack in crypto history stole less than $50: SEAL

Last updated: September 9, 2025 4:15 am
Published: 6 months ago
Share

Hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries, targeting crypto wallets.

Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.

Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.

Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X:

“Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.”

The $50 figure was, however, bumped up from 5 cents a few hours earlier, suggesting the potential damage may still be unfolding.

The 5 cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.

Related: Pokémon cards will soon have their ‘Polymarket moment’ — Bitwise

The breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

The attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Ledger’s chief technology officer Charles Guillemet was among many who have urged crypto users to proceed with caution when confirming onchain transactions.

This is a developing story, and further information will be added as it becomes available.

Read more on Cointelegraph

This news is powered by Cointelegraph Cointelegraph

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Analyzing the 2026 Crypto Presale Landscape: ZKP, DeepSnitch AI, LiquidChain, and AgoraLend – Crypto Economy
Citadel CEO holds 4.5% stake in Solana treasury DeFi Dev Corp
Binance Confirms Massive Crypto Holdings in Latest Proof of Reserves – Crypto Economy
Hong Kong will fully implement new banking capital rules based on the Basel Committee’s crypto regulations on January 1. – Lookonchain – Looking for smartmoney onchain
Aptos Surpasses Ethereum in Stablecoin Inflows

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article 3 Altcoins That Could Hit All Time High This Week
Next Article Ethereum L2 MegaETH introduces yield-bearing stablecoin to fund protocol
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d