No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Friday, February 27, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries

by TheAdviserMagazine
6 months ago
in Cryptocurrency
Reading Time: 2 mins read
A A
NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries
Share on FacebookShare on TwitterShare on LInkedIn


Hackers have compromised widely used JavaScript software libraries in what’s being called the largest supply chain attack in history. The injected malware is reportedly designed to steal crypto by swapping wallet addresses and intercepting transactions.

According to several reports on Monday, hackers broke into the node package manager (NPM) account of a well-known developer and secretly added malware to popular JavaScript libraries used by millions of apps.

The malicious code swaps or hijacks crypto wallet addresses, potentially putting many projects at risk.

“There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised,” Ledger Chief Technology Officer Charles Guillemet warned on Monday. “The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.”

Source: Minal Thukral

The breach targeted packages such as chalk, strip-ansi and color-convert — small utilities buried deep in the dependency trees of countless projects. Together, these libraries are downloaded more than a billion times each week, meaning even developers who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Security researchers warned that users relying on software wallets may be especially vulnerable, while those confirming every transaction on a hardware wallet are protected.

Phishing emails gave attackers access to NPM maintainer accounts

Attackers sent emails posing as official NPM support, warning maintainers that their accounts would be locked unless they “updated” two-factor authentication by September 10.

The fake site captured login credentials, giving hackers control over a maintainer’s account. Once inside, the attackers pushed malicious updates to packages with billions of weekly downloads.

Charlie Eriksen, a researcher at Aikido Security, told BleepingComputer the attack was especially dangerous because it operated “at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

JavaScript, Hackers
Phishing email sent to JavaScript developers on Monday. Source: Github/Burnett01

This is a developing story, and further information will be added as it becomes available.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users



Source link

Tags: attackCoreCryptoStealingInjectsJavaScriptLibrariesMalwareNPM
ShareTweetShare
Previous Post

Signet (SIG) remains well-positioned for its all-important season, here’s why

Next Post

5 Dividend “Rules” That Don’t Hold Up in 2025

Related Posts

edit post
Ripple Unveils Whitepaper On Institutional Digital Asset Trading

Ripple Unveils Whitepaper On Institutional Digital Asset Trading

by TheAdviserMagazine
February 27, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ripple has published a new whitepaper arguing...

edit post
Bitwise CIO Calls Bitcoin Selloff ‘Classic Cycle,’ Dismisses Manipulation Rumors

Bitwise CIO Calls Bitcoin Selloff ‘Classic Cycle,’ Dismisses Manipulation Rumors

by TheAdviserMagazine
February 27, 2026
0

Bitcoin’s latest decline has reignited claims of market manipulation, with many pointing fingers at major firms like Jane Street. But...

edit post
Bitcoin Spot Volumes Sink To 2024 Lows, Coinbase Selling Eases

Bitcoin Spot Volumes Sink To 2024 Lows, Coinbase Selling Eases

by TheAdviserMagazine
February 26, 2026
0

Bitcoin spot trading activity has fallen to its weakest level of the year even as a fresh CryptoQuant signal suggests...

edit post
Senator Blumenthal Demands Binance Records Over Alleged .7B Iran Sanctions Breach

Senator Blumenthal Demands Binance Records Over Alleged $1.7B Iran Sanctions Breach

by TheAdviserMagazine
February 26, 2026
0

A U.S. Senator has launched a formal Senate Homeland Security Committee inquiry into Binance following reports that the exchange facilitated...

edit post
Can Ethereum’s Strawmap propel it to ,000 by 2029?

Can Ethereum’s Strawmap propel it to $10,000 by 2029?

by TheAdviserMagazine
February 26, 2026
0

Ethereum’s latest long-term planning document has given investors a new way to assess whether the digital asset can eventually reach...

edit post
Bitcoin Adoption Booms While Bear Market Deepens: Watch These Signals

Bitcoin Adoption Booms While Bear Market Deepens: Watch These Signals

by TheAdviserMagazine
February 26, 2026
0

Since dropping by 35% between Jan. 14 and Feb. 5, Bitcoin (BTC) has consolidated in a range between $60,000 to...

Next Post
edit post
5 Dividend “Rules” That Don’t Hold Up in 2025

5 Dividend “Rules” That Don’t Hold Up in 2025

edit post
10 Portfolio Rebalancing Mistakes Investors Keep Repeating

10 Portfolio Rebalancing Mistakes Investors Keep Repeating

  • Trending
  • Comments
  • Latest
edit post
Foreclosure Starts are Up 19%—These Counties are Seeing the Highest Distress

Foreclosure Starts are Up 19%—These Counties are Seeing the Highest Distress

February 24, 2026
edit post
Medicare Fraud In California – 2.5% Of The Population Accounts For 18% Of NATIONWIDE Healthcare Spending

Medicare Fraud In California – 2.5% Of The Population Accounts For 18% Of NATIONWIDE Healthcare Spending

February 3, 2026
edit post
North Carolina Updates How Wills Can Be Stored

North Carolina Updates How Wills Can Be Stored

February 10, 2026
edit post
Gasoline-starved California is turning to fuel from the Bahamas

Gasoline-starved California is turning to fuel from the Bahamas

February 15, 2026
edit post
Where Is My 2025 Oregon State Tax Refund

Where Is My 2025 Oregon State Tax Refund

February 13, 2026
edit post
7 States Reporting a Surge in Norovirus Cases

7 States Reporting a Surge in Norovirus Cases

February 22, 2026
edit post
Hindenburg Omen: Rotation Signal or Early Distribution?

Hindenburg Omen: Rotation Signal or Early Distribution?

0
edit post
China to dominate the global plastics demand in 2026

China to dominate the global plastics demand in 2026

0
edit post
FP’s February CE quiz available now to planners

FP’s February CE quiz available now to planners

0
edit post
Scientists Test Nasal Spray Vaccine That Protected Mice From COVID, Flu, and Pneumonia for Months

Scientists Test Nasal Spray Vaccine That Protected Mice From COVID, Flu, and Pneumonia for Months

0
edit post
Teamwork in Learning Is Passé: How Guided Independence Builds Deep Learning – Faculty Focus

Teamwork in Learning Is Passé: How Guided Independence Builds Deep Learning – Faculty Focus

0
edit post
How the Big Beautiful Bill Could Affect Self-Employed Deductions

How the Big Beautiful Bill Could Affect Self-Employed Deductions

0
edit post
China to dominate the global plastics demand in 2026

China to dominate the global plastics demand in 2026

February 27, 2026
edit post
An 1863 Investment in Gold Coins Is Worth Millions in the 21st Century. Should You Adopt the Same Strategy?

An 1863 Investment in Gold Coins Is Worth Millions in the 21st Century. Should You Adopt the Same Strategy?

February 27, 2026
edit post
New York City cops actually arrested someone for getting in a snowball fight with them

New York City cops actually arrested someone for getting in a snowball fight with them

February 27, 2026
edit post
Ripple Unveils Whitepaper On Institutional Digital Asset Trading

Ripple Unveils Whitepaper On Institutional Digital Asset Trading

February 27, 2026
edit post
FP’s February CE quiz available now to planners

FP’s February CE quiz available now to planners

February 27, 2026
edit post
Sam’s Links: February Edition – Econlib

Sam’s Links: February Edition – Econlib

February 27, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • China to dominate the global plastics demand in 2026
  • An 1863 Investment in Gold Coins Is Worth Millions in the 21st Century. Should You Adopt the Same Strategy?
  • New York City cops actually arrested someone for getting in a snowball fight with them
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.