Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack

CryptoExpert by CryptoExpert
September 9, 2025
in Blockchain News
0
Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack
  • Facebook
  • Twitter
  • Pinterest


You might also like

DeFi Could Reach $2.7T as Tokenization Expands: StanChart

Top Projects from Anthropic Opus 4.7 Hackathon Announced

Strategy Buys 1,587 BTC for $100M, Lowers Average Cost Basis

Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.

Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.

Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X:

”Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.”

Source: Security Alliance

The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding.

okex

ETH, memecoin among small amount of crypto stolen

The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said.

Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.

Crypto projects that didn’t download the NPMs still at risk

The breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Related: Pokémon cards will soon have their ‘Polymarket moment’ — Bitwise

The attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Ledger chief technology officer Charles Guillemet was among many who have urged crypto users to proceed with caution when confirming onchain transactions.

In a separate post, Ledger said its devices weren’t directly affected by the NPM attack.

You won’t be instantly drained, crypto founder says

0xngmi, the pseudonymous founder of crypto analytics platform DeFiLlama, however said only crypto projects that updated after the malware-infected NPM package was published may be at risk, and even then, users must approve the malicious transaction for it to work.

Though like Guillemet, he said it may be safer to avoid using crypto websites until developers behind those platforms clean up the bad packages.

This is a developing story, and further information will be added as it becomes available.

Magazine: ‘Accidental jailbreaks’ and ChatGPT’s links to murder, suicide: AI Eye



Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Ethereum
CryptoExpert

CryptoExpert

Recommended For You

DeFi Could Reach $2.7T as Tokenization Expands: StanChart

by CryptoExpert
June 16, 2026
0
Cointelegraph

Standard Chartered expects assets locked in decentralized finance (DeFi) to grow 37-fold to $2.7 trillion by the end of 2030.The expansion would be driven by both tokenized real-world...

Read more

Top Projects from Anthropic Opus 4.7 Hackathon Announced

by CryptoExpert
June 16, 2026
0
Claude Managed Agents Add Scheduling, Secure CLI Access

Zach Anderson Jun 15, 2026 22:08 Anthropic's Opus 4.7 hackathon showcased innovative AI-driven apps in medical training, electronics repair, and education. Winners include MedKit...

Read more

Strategy Buys 1,587 BTC for $100M, Lowers Average Cost Basis

by CryptoExpert
June 16, 2026
0
10BedICU Leverages OpenAI's API to Revolutionize Critical Care in India

Timothy Morano Jun 15, 2026 14:14 Michael Saylor’s Strategy acquired 1,587 BTC for $100M, funded through MSTR stock sales, bringing its total holdings to...

Read more

Pudgy Penguins Winds Down Pudgy Party After 1M Downloads

by CryptoExpert
June 15, 2026
0
Cointelegraph

Non-fungible token (NFT) project Pudgy Penguins is winding down its mobile game Pudgy Party and halting further development.In an X post, the team said on Saturday that it...

Read more

Barron’s data shift nudges Polymarket odds as 2028 race stays lively

by CryptoExpert
June 15, 2026
0
Barron’s data shift nudges Polymarket odds as 2028 race stays lively

Rongchai Wang Jun 14, 2026 18:15 Polymarket’s 2028 presidential contracts see brisk turnover after Barron’s data previews this week. Barron’s data...

Read more
Next Post
Coinpedia - Fintech & Cryptocurreny News Media

CleanCore Buys 285.42M Dogecoin and Sets 1B DOGE in 30 Days

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 65,680.00
ethereum
Ethereum (ETH) $ 1,790.66
tether
Tether (USDT) $ 0.999048
bnb
BNB (BNB) $ 605.73
xrp
XRP (XRP) $ 1.22
usd-coin
USDC (USDC) $ 0.999919
solana
Solana (SOL) $ 73.70
tron
TRON (TRX) $ 0.316341
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?