The post Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack appeared on BitcoinEthereumNews.com. Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say. Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said. Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X: ”Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.” Source: Security Alliance “The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized,” pseudonymous SEAL security researcher Samczsun told Cointelegraph in a separate comment. The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding. ETH, memecoin among small amount of crypto stolen The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far. Crypto projects that didn’t download the NPMs still at… The post Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack appeared on BitcoinEthereumNews.com. Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say. Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said. Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X: ”Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.” Source: Security Alliance “The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized,” pseudonymous SEAL security researcher Samczsun told Cointelegraph in a separate comment. The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding. ETH, memecoin among small amount of crypto stolen The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far. Crypto projects that didn’t download the NPMs still at…

Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack

2025/09/09 20:32

Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.

Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.

Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X:

Source: Security Alliance

“The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized,” pseudonymous SEAL security researcher Samczsun told Cointelegraph in a separate comment.

The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding.

ETH, memecoin among small amount of crypto stolen

The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said.

Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.

Crypto projects that didn’t download the NPMs still at risk

The breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Related: Pokémon cards will soon have their ‘Polymarket moment’ — Bitwise

The attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Ledger chief technology officer Charles Guillemet was among many who have urged crypto users to proceed with caution when confirming onchain transactions.

Ledger, MetaMask among crypto apps not affected

Crypto wallet providers Ledger and MetaMask marked their platforms as safe from the NPM attack — pointing to “multiple layers of defense” to protect against such attacks.

The team behind Phantom Wallet said it doesn’t use any vulnerable versions of the affected packages, while Uniswap noted that none of its apps are at risk.

Aerodrome, Blast, Blockstream Jade and Revoke.cash were among the other crypto platforms that said they were unaffected by the supply chain attack.

Source: MetaMask

You won’t be instantly drained, crypto founder says

0xngmi, the pseudonymous founder of crypto analytics platform DefiLlama, however said only crypto projects that updated after the malware-infected NPM package was published may be at risk. Even then, users must approve the malicious transaction for it to work.

Though like Guillemet, he said it may be safer to avoid using crypto websites until developers behind those platforms clean up the bad packages.

Magazine: ‘Accidental jailbreaks’ and ChatGPT’s links to murder, suicide: AI Eye

Source: https://cointelegraph.com/news/large-scale-npm-attack-compromised-less-50-dollars?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Satoshi Upgrades By Stacks Set To Change Bitcoin Into Authentic Global Financial Cash

Satoshi Upgrades By Stacks Set To Change Bitcoin Into Authentic Global Financial Cash

The post Satoshi Upgrades By Stacks Set To Change Bitcoin Into Authentic Global Financial Cash appeared on BitcoinEthereumNews.com. Stacks blockchain has announced major upgrades to its infrastructure through ‘Satoshi Upgrades’, aiming to transform the Bitcoin trade in the global financial ecosystem. The upgrade package brings self-custodial sBTC support, allowing users to make use of the full potential of applications based on Web 2 on the basis of taking the risk with their assets. It is a crucial change that may allow the dormant capitalism to release trillions of dollars currently tied up in Bitcoin as an idle form of store of value. Self-Custodial sBTC – Providing Users With Control and Dynamic Utility Apart from the major updates around the corner, one selling feature of Satoshi Upgrades by Stacks is the full self-custodial sBTC solution. Moreover the asset provides you with the  and the possibility of it to combat entry barriers of one of the most critical obstacles to the popularization of Bitcoin DeFi. In contrast to existing wrapped Bitcoin designs where third-party custodians direct users to trust the security of their implementation, creating Stacks products means that individual users can be able to program Bitcoin as they themselves think it should, and that best practices in cryptography and security are not violated. Its technical architecture is based on the special consensus mechanism provided by Stacks which pegs itself directly on the blockchain of Bitcoin. This forms a minimal trust bridge between the base layer of Bitcoin and the smart contract functionality. This design allows seeking the unavailability of the single points of failure which were characteristic of other Bitcoin Layer 2 solutions in addition to institutional-grade security. Growing Ecosystem Adoption and Institutional Infrastructure Stacks has positioned itself strategically to institutionalize the capture of Bitcoin capital by selling its broad and wide stretches of custody provider partnerships. A number of custody providers have already been onboarded to support sBTC,…
Share
BitcoinEthereumNews2025/09/22 14:16
Gold price in Pakistan: Rates on October 20

Gold price in Pakistan: Rates on October 20

The post Gold price in Pakistan: Rates on October 20 appeared on BitcoinEthereumNews.com. Gold prices rose in Pakistan on Monday, according to data compiled by FXStreet. The price for Gold stood at 38,917.76 Pakistani Rupees (PKR) per gram, up compared with the PKR 38,779.00 it cost on Friday. The price for Gold increased to PKR 453,929.20 per tola from PKR 452,310.70 per tola on friday. Unit measure Gold Price in PKR 1 Gram 38,917.76 10 Grams 389,160.30 Tola 453,929.20 Troy Ounce 1,210,479.00 FXStreet calculates Gold prices in Pakistan by adapting international prices (USD/PKR) to the local currency and measurement units. Prices are updated daily based on the market rates taken at the time of publication. Prices are just for reference and local rates could diverge slightly. Gold FAQs Gold has played a key role in human’s history as it has been widely used as a store of value and medium of exchange. Currently, apart from its shine and usage for jewelry, the precious metal is widely seen as a safe-haven asset, meaning that it is considered a good investment during turbulent times. Gold is also widely seen as a hedge against inflation and against depreciating currencies as it doesn’t rely on any specific issuer or government. Central banks are the biggest Gold holders. In their aim to support their currencies in turbulent times, central banks tend to diversify their reserves and buy Gold to improve the perceived strength of the economy and the currency. High Gold reserves can be a source of trust for a country’s solvency. Central banks added 1,136 tonnes of Gold worth around $70 billion to their reserves in 2022, according to data from the World Gold Council. This is the highest yearly purchase since records began. Central banks from emerging economies such as China, India and Turkey are quickly increasing their Gold reserves. Gold has an inverse correlation with…
Share
BitcoinEthereumNews2025/10/20 13:27
Fed expected to cut rates by 25 bps, Bitcoin and Ethereum steady

Fed expected to cut rates by 25 bps, Bitcoin and Ethereum steady

The post Fed expected to cut rates by 25 bps, Bitcoin and Ethereum steady appeared on BitcoinEthereumNews.com. News Jenny Johnson predicts a 25 basis point Fed rate cut, citing strong wage growth and retail sales despite sticky 3% inflation. Scott Melker expects a cautious 25 basis point cut, with Powell’s speech focusing on data driven decisions. Bitcoin and Ethereum are steady, but a hint of more cuts by year-end could spark a market rally. The Federal Reserve announced its interest rate decision. On CNBC, Jenny Johnson, the CEO of Franklin Templeton, shared her take, betting on a small 25 basis point rate cut rather than a bigger 50 basis point one. She mentioned recent job numbers that show a softening labor market, but she thinks those figures are old news. Instead, she pointed to strong wage growth and growing retail sales, which show people are still spending despite inflation hanging around 3%. What’s Driving the Fed’s Next Move Johnson feels a 25 basis point cut is the smart play for Fed Chair Jerome Powell. She noted there’s room to cut rates more in October or December if the economy calls for it. The economy looks solid, she said, but Powell’s comments at Jackson Hole about a weaker job market mean no rate cut isn’t an option. Market expert Scott Melker agrees, expecting a cautious 25 basis point cut, with Powell likely to stress that future moves depend on data without promising more cuts soon. Meanwhile, former President Donald Trump is pushing for a larger cut. Bitcoin, Ethereum, and other cryptocurrencies are holding steady as investors wait for Powell’s speech. Analyst Kevin Capital says the market already expects the cut, but if Powell hints at more cuts by year-end, we could see a rally. Everyone’s watching to see what Powell says next. Source: https://thenewscrypto.com/fed-expected-to-cut-rates-by-25-bps-bitcoin-and-ethereum-steady/
Share
BitcoinEthereumNews2025/09/18 12:46