Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack

CryptoExpert by CryptoExpert
September 9, 2025
in Blockchain News
0
Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack
  • Facebook
  • Twitter
  • Pinterest


You might also like

What is Proof of Stake (PoS) vs. Proof of Work (PoW)?

Polygon Reduces Block Production Time to 1.75 Seconds

Bitwise: Stablecoin Adoption by Tech Giants Could Propel $4T Market

Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.

Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.

Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X:

”Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.”

Source: Security Alliance

The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding.

okex

ETH, memecoin among small amount of crypto stolen

The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said.

Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.

Crypto projects that didn’t download the NPMs still at risk

The breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Related: Pokémon cards will soon have their ‘Polymarket moment’ — Bitwise

The attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Ledger chief technology officer Charles Guillemet was among many who have urged crypto users to proceed with caution when confirming onchain transactions.

In a separate post, Ledger said its devices weren’t directly affected by the NPM attack.

You won’t be instantly drained, crypto founder says

0xngmi, the pseudonymous founder of crypto analytics platform DeFiLlama, however said only crypto projects that updated after the malware-infected NPM package was published may be at risk, and even then, users must approve the malicious transaction for it to work.

Though like Guillemet, he said it may be safer to avoid using crypto websites until developers behind those platforms clean up the bad packages.

This is a developing story, and further information will be added as it becomes available.

Magazine: ‘Accidental jailbreaks’ and ChatGPT’s links to murder, suicide: AI Eye



Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Ethereum
CryptoExpert

CryptoExpert

Recommended For You

What is Proof of Stake (PoS) vs. Proof of Work (PoW)?

by CryptoExpert
May 8, 2026
0
What is Proof of Stake (PoS) vs. Proof of Work (PoW)?

Proof of Work (PoW) and Proof of Stake (PoS) are the two primary consensus mechanisms blockchains use to verify transactions and secure their networks without a central authority....

Read more

Polygon Reduces Block Production Time to 1.75 Seconds

by CryptoExpert
May 8, 2026
0
Cointelegraph

Blockchain layer-2 (L2) network Polygon reduced its average block time by 250 milliseconds to 1.75 seconds, marking its first block-time reduction since genesis as the network pushes deeper...

Read more

Bitwise: Stablecoin Adoption by Tech Giants Could Propel $4T Market

by CryptoExpert
May 7, 2026
0
Pyth Network Integrates Price Oracles with IOTA EVM

Rongchai Wang May 07, 2026 03:41 Bitwise sees stablecoin market scaling to $4 trillion by 2030 if tech giants like Meta and DoorDash embrace...

Read more

Quantum Also Adds Proof-of-Ownership Headaches

by CryptoExpert
May 7, 2026
0
Cointelegraph

Blockchain protocols preparing for the quantum computing threat should also consider how to quickly verify ownership on the blockchain if funds are stolen, the development and research team...

Read more

Coinbase Sued Over $55M Frozen Funds Tied to DeFi Saver Exploit

by CryptoExpert
May 7, 2026
0
AssemblyAI Introduces German STT and Enhances PII Detection

Joerg Hiller May 06, 2026 12:26 Coinbase faces lawsuit for withholding crypto linked to a $55M DeFi Saver hack, raising questions about exchanges' roles...

Read more
Next Post
Coinpedia - Fintech & Cryptocurreny News Media

CleanCore Buys 285.42M Dogecoin and Sets 1B DOGE in 30 Days

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 80,208.00
ethereum
Ethereum (ETH) $ 2,289.09
tether
Tether (USDT) $ 0.999852
bnb
BNB (BNB) $ 639.94
xrp
XRP (XRP) $ 1.39
usd-coin
USDC (USDC) $ 0.999839
solana
Solana (SOL) $ 88.51
tron
TRON (TRX) $ 0.347986
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.00
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?