No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Friday, February 6, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries

by TheAdviserMagazine
5 months ago
in Cryptocurrency
Reading Time: 2 mins read
A A
NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries
Share on FacebookShare on TwitterShare on LInkedIn


Hackers have compromised widely used JavaScript software libraries in what’s being called the largest supply chain attack in history. The injected malware is reportedly designed to steal crypto by swapping wallet addresses and intercepting transactions.

According to several reports on Monday, hackers broke into the node package manager (NPM) account of a well-known developer and secretly added malware to popular JavaScript libraries used by millions of apps.

The malicious code swaps or hijacks crypto wallet addresses, potentially putting many projects at risk.

“There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised,” Ledger Chief Technology Officer Charles Guillemet warned on Monday. “The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.”

Source: Minal Thukral

The breach targeted packages such as chalk, strip-ansi and color-convert — small utilities buried deep in the dependency trees of countless projects. Together, these libraries are downloaded more than a billion times each week, meaning even developers who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Security researchers warned that users relying on software wallets may be especially vulnerable, while those confirming every transaction on a hardware wallet are protected.

Phishing emails gave attackers access to NPM maintainer accounts

Attackers sent emails posing as official NPM support, warning maintainers that their accounts would be locked unless they “updated” two-factor authentication by September 10.

The fake site captured login credentials, giving hackers control over a maintainer’s account. Once inside, the attackers pushed malicious updates to packages with billions of weekly downloads.

Charlie Eriksen, a researcher at Aikido Security, told BleepingComputer the attack was especially dangerous because it operated “at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

JavaScript, Hackers
Phishing email sent to JavaScript developers on Monday. Source: Github/Burnett01

This is a developing story, and further information will be added as it becomes available.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users



Source link

Tags: attackCoreCryptoStealingInjectsJavaScriptLibrariesMalwareNPM
ShareTweetShare
Previous Post

Signet (SIG) remains well-positioned for its all-important season, here’s why

Next Post

5 Dividend “Rules” That Don’t Hold Up in 2025

Related Posts

edit post
Peter Brandt Forecasts $BTC Drop To K: $MAXI Digs In

Peter Brandt Forecasts $BTC Drop To $42K: $MAXI Digs In

by TheAdviserMagazine
February 6, 2026
0

What to Know: Bitcoin’s slide toward the mid-$60Ks has reignited downside targets like $42K, especially as liquidity and sentiment wobble....

edit post
Bybit Partners With Mercuryo for Crypto Transactions; Enables Direct AED Bank Transfers

Bybit Partners With Mercuryo for Crypto Transactions; Enables Direct AED Bank Transfers

by TheAdviserMagazine
February 6, 2026
0

Blueberry Broker Review 2026: Regulation, Platforms, Fees & Trading Conditions | Finance Magnates Blueberry Broker Review 2026: Regulation, Platforms, Fees...

edit post
Top Crypto Exchanges in February 2026 – Updated Rankings as Q1 Develops

Top Crypto Exchanges in February 2026 – Updated Rankings as Q1 Develops

by TheAdviserMagazine
February 6, 2026
0

Disclosure: This article contains affiliate links. If you click a link and make a purchase or sign up for a...

edit post
Large Bitcoin Holders Supply Hits 9-Month Low

Large Bitcoin Holders Supply Hits 9-Month Low

by TheAdviserMagazine
February 6, 2026
0

Large Bitcoin holders are now controlling the smallest share of the cryptocurrency’s supply since late May, when it first reclaimed...

edit post
Amazon stock sinks 10% despite earnings beat on 0B capex shock

Amazon stock sinks 10% despite earnings beat on $200B capex shock

by TheAdviserMagazine
February 5, 2026
0

Amazon said Thursday it plans to spend $200 billion on capital expenditures in 2026, with a focus on artificial intelligence...

edit post
Ethereum Network Activity Breaks Records Even As ETH Price Stalls

Ethereum Network Activity Breaks Records Even As ETH Price Stalls

by TheAdviserMagazine
February 5, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The Ethereum network and its price are...

Next Post
edit post
5 Dividend “Rules” That Don’t Hold Up in 2025

5 Dividend “Rules” That Don’t Hold Up in 2025

edit post
10 Portfolio Rebalancing Mistakes Investors Keep Repeating

10 Portfolio Rebalancing Mistakes Investors Keep Repeating

  • Trending
  • Comments
  • Latest
edit post
Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a 8 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a $348 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

January 10, 2026
edit post
Utility Shutoff Policies Are Changing in Several Midwestern States

Utility Shutoff Policies Are Changing in Several Midwestern States

January 9, 2026
edit post
Medicare Fraud In California – 2.5% Of The Population Accounts For 18% Of NATIONWIDE Healthcare Spending

Medicare Fraud In California – 2.5% Of The Population Accounts For 18% Of NATIONWIDE Healthcare Spending

February 3, 2026
edit post
Tennessee theater professor reinstated, with 0,000 settlement, after losing his job over a Charlie Kirk-related social media post

Tennessee theater professor reinstated, with $500,000 settlement, after losing his job over a Charlie Kirk-related social media post

January 8, 2026
edit post
Key Nevada legislator says lawmakers will push for independent audit of altered public record in Nevada OSHA’s Boring Company inspection 

Key Nevada legislator says lawmakers will push for independent audit of altered public record in Nevada OSHA’s Boring Company inspection 

February 4, 2026
edit post
Where Is My South Carolina Tax Refund

Where Is My South Carolina Tax Refund

January 30, 2026
edit post
Bybit Partners With Mercuryo for Crypto Transactions; Enables Direct AED Bank Transfers

Bybit Partners With Mercuryo for Crypto Transactions; Enables Direct AED Bank Transfers

0
edit post
Is Life Insurance Expensive? A Real-World Cost Breakdown

Is Life Insurance Expensive? A Real-World Cost Breakdown

0
edit post
ASML: KI-Monopolist bereitet den nächsten Sprung vor!

ASML: KI-Monopolist bereitet den nächsten Sprung vor!

0
edit post
Fractal Analytics raises Rs 1,249 crore from anchor investors ahead of IPO; Morgan Stanley, Goldman Sachs among key backers

Fractal Analytics raises Rs 1,249 crore from anchor investors ahead of IPO; Morgan Stanley, Goldman Sachs among key backers

0
edit post
How To Survive a Market Selloff

How To Survive a Market Selloff

0
edit post
Sam Altman should take Niklas Ostberg’s number—what the Delivery Hero founder doesn’t know about taking a company public and handling grumpy shareholders isn’t worth knowing 

Sam Altman should take Niklas Ostberg’s number—what the Delivery Hero founder doesn’t know about taking a company public and handling grumpy shareholders isn’t worth knowing 

0
edit post
Fractal Analytics raises Rs 1,249 crore from anchor investors ahead of IPO; Morgan Stanley, Goldman Sachs among key backers

Fractal Analytics raises Rs 1,249 crore from anchor investors ahead of IPO; Morgan Stanley, Goldman Sachs among key backers

February 6, 2026
edit post
ASML: KI-Monopolist bereitet den nächsten Sprung vor!

ASML: KI-Monopolist bereitet den nächsten Sprung vor!

February 6, 2026
edit post
How To Survive a Market Selloff

How To Survive a Market Selloff

February 6, 2026
edit post
Peter Brandt Forecasts $BTC Drop To K: $MAXI Digs In

Peter Brandt Forecasts $BTC Drop To $42K: $MAXI Digs In

February 6, 2026
edit post
Sam Altman should take Niklas Ostberg’s number—what the Delivery Hero founder doesn’t know about taking a company public and handling grumpy shareholders isn’t worth knowing 

Sam Altman should take Niklas Ostberg’s number—what the Delivery Hero founder doesn’t know about taking a company public and handling grumpy shareholders isn’t worth knowing 

February 6, 2026
edit post
Is Life Insurance Expensive? A Real-World Cost Breakdown

Is Life Insurance Expensive? A Real-World Cost Breakdown

February 6, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Fractal Analytics raises Rs 1,249 crore from anchor investors ahead of IPO; Morgan Stanley, Goldman Sachs among key backers
  • ASML: KI-Monopolist bereitet den nächsten Sprung vor!
  • How To Survive a Market Selloff
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.