No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Sunday, June 21, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries

by TheAdviserMagazine
10 months ago
in Cryptocurrency
Reading Time: 2 mins read
A A
NPM Attack Injects Crypto-Stealing Malware Into Core JavaScript Libraries
Share on FacebookShare on TwitterShare on LInkedIn


Hackers have compromised widely used JavaScript software libraries in what’s being called the largest supply chain attack in history. The injected malware is reportedly designed to steal crypto by swapping wallet addresses and intercepting transactions.

According to several reports on Monday, hackers broke into the node package manager (NPM) account of a well-known developer and secretly added malware to popular JavaScript libraries used by millions of apps.

The malicious code swaps or hijacks crypto wallet addresses, potentially putting many projects at risk.

“There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised,” Ledger Chief Technology Officer Charles Guillemet warned on Monday. “The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.”

Source: Minal Thukral

The breach targeted packages such as chalk, strip-ansi and color-convert — small utilities buried deep in the dependency trees of countless projects. Together, these libraries are downloaded more than a billion times each week, meaning even developers who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Security researchers warned that users relying on software wallets may be especially vulnerable, while those confirming every transaction on a hardware wallet are protected.

Phishing emails gave attackers access to NPM maintainer accounts

Attackers sent emails posing as official NPM support, warning maintainers that their accounts would be locked unless they “updated” two-factor authentication by September 10.

The fake site captured login credentials, giving hackers control over a maintainer’s account. Once inside, the attackers pushed malicious updates to packages with billions of weekly downloads.

Charlie Eriksen, a researcher at Aikido Security, told BleepingComputer the attack was especially dangerous because it operated “at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

JavaScript, Hackers
Phishing email sent to JavaScript developers on Monday. Source: Github/Burnett01

This is a developing story, and further information will be added as it becomes available.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users



Source link

Tags: attackCoreCryptoStealingInjectsJavaScriptLibrariesMalwareNPM
ShareTweetShare
Previous Post

Signet (SIG) remains well-positioned for its all-important season, here’s why

Next Post

5 Dividend “Rules” That Don’t Hold Up in 2025

Related Posts

edit post
Ethereum Foundation Details Clear Signing Standards to Fight Phishing

Ethereum Foundation Details Clear Signing Standards to Fight Phishing

by TheAdviserMagazine
June 21, 2026
0

The Ethereum Foundation has laid out new security standards for crypto wallets designed to make transaction approvals much clearer for...

edit post
Hunting the Next Marvel? Jensen Huang Already Shared Clues on One Slide

Hunting the Next Marvel? Jensen Huang Already Shared Clues on One Slide

by TheAdviserMagazine
June 21, 2026
0

Key TakeawaysJensen Huang’s 2026 AI factory map spotlighted NVIDIA’s DSX buildout framework.Marvell gained 241% YTD; AI infrastructure firms may see...

edit post
Bitcoin ETFs Shed a Record .4B in 30 Days

Bitcoin ETFs Shed a Record $6.4B in 30 Days

by TheAdviserMagazine
June 21, 2026
0

US-listed spot Bitcoin exchange-traded funds recorded their largest 30-day net outflow since launching in January 2024 amid a crypto bear...

edit post
ETH/BTC Ratio Falls Back To Early-2023 Levels As Traders Deb

ETH/BTC Ratio Falls Back To Early-2023 Levels As Traders Deb

by TheAdviserMagazine
June 20, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure TL;DR Woetoe says the ETH/BTC ratio...

edit post
Is Bitcoin Dead? Galaxy CEO Says Surprise Fed Factor Could Prove Critics Wrong

Is Bitcoin Dead? Galaxy CEO Says Surprise Fed Factor Could Prove Critics Wrong

by TheAdviserMagazine
June 20, 2026
0

Bitcoin has failed to pick up any steam in recent months, and there has been fresh talk that the BTC...

edit post
Why a resilient jobs market keeps turning into a Bitcoin sell signal

Why a resilient jobs market keeps turning into a Bitcoin sell signal

by TheAdviserMagazine
June 20, 2026
0

Good news for the American worker came at the worst possible moment for Bitcoin. Initial jobless claims fell by 4,000...

Next Post
edit post
5 Dividend “Rules” That Don’t Hold Up in 2025

5 Dividend “Rules” That Don’t Hold Up in 2025

edit post
10 Portfolio Rebalancing Mistakes Investors Keep Repeating

10 Portfolio Rebalancing Mistakes Investors Keep Repeating

  • Trending
  • Comments
  • Latest
edit post
5 Pennsylvania Rebate Rules Seniors Should Check Before the Property Tax/Rent Deadline

5 Pennsylvania Rebate Rules Seniors Should Check Before the Property Tax/Rent Deadline

June 18, 2026
edit post
New York Seniors: 6 STAR Tax Relief Rules That Could Put a Bigger Check in Your Mailbox

New York Seniors: 6 STAR Tax Relief Rules That Could Put a Bigger Check in Your Mailbox

June 20, 2026
edit post
Florida Roads Become a Battleground for Illegal Immigration

Florida Roads Become a Battleground for Illegal Immigration

June 9, 2026
edit post
Louisiana’s Age-Tiered Homestead Exemption: 8 Details About the Proposed 2028 Amendment

Louisiana’s Age-Tiered Homestead Exemption: 8 Details About the Proposed 2028 Amendment

June 15, 2026
edit post
The 8 States That Still Tax Social Security in 2026

The 8 States That Still Tax Social Security in 2026

June 6, 2026
edit post
It’s Time To Talk About Massie

It’s Time To Talk About Massie

May 23, 2026
edit post
Israeli delegation to visit US to promote IAI, Rafael IPOs

Israeli delegation to visit US to promote IAI, Rafael IPOs

0
edit post
AI Agents Need Real-Time Context: Data Streaming Is How You Are Going To Get It

AI Agents Need Real-Time Context: Data Streaming Is How You Are Going To Get It

0
edit post
The Divide Is No Longer Left Vs Right

The Divide Is No Longer Left Vs Right

0
edit post
"Always Up for a Good Battle": CME Takes Aim at CFTC in High-Stakes Lawsuit Over Perps

"Always Up for a Good Battle": CME Takes Aim at CFTC in High-Stakes Lawsuit Over Perps

0
edit post
Jim Cramer Calls Marriott “The Best” Among Hotel Companies

Jim Cramer Calls Marriott “The Best” Among Hotel Companies

0
edit post
How Kevin Warsh has set out to remake the Fed

How Kevin Warsh has set out to remake the Fed

0
edit post
Israeli delegation to visit US to promote IAI, Rafael IPOs

Israeli delegation to visit US to promote IAI, Rafael IPOs

June 21, 2026
edit post
How Kevin Warsh has set out to remake the Fed

How Kevin Warsh has set out to remake the Fed

June 21, 2026
edit post
Tenzin Seldon: The GLP-1 boom is the biggest climate story no one is pricing in

Tenzin Seldon: The GLP-1 boom is the biggest climate story no one is pricing in

June 21, 2026
edit post
Unpacking the Fragile MOU Between the US and Iran

Unpacking the Fragile MOU Between the US and Iran

June 21, 2026
edit post
Ethereum Foundation Details Clear Signing Standards to Fight Phishing

Ethereum Foundation Details Clear Signing Standards to Fight Phishing

June 21, 2026
edit post
Aaron Frenkel’s suicide drone co UVision plans Nasdaq IPO

Aaron Frenkel’s suicide drone co UVision plans Nasdaq IPO

June 21, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Israeli delegation to visit US to promote IAI, Rafael IPOs
  • How Kevin Warsh has set out to remake the Fed
  • Tenzin Seldon: The GLP-1 boom is the biggest climate story no one is pricing in
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.