Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Crypto

NPM attack nets cybercriminals less than $50

Newsroom by Newsroom
September 11, 2025
in Crypto
bitcoin
Share on FacebookShare on TwitterShare on Linkedin

Hackers compromised the account of an NPM developer, installing malware in JavaScript libraries downloaded more than two billion times.

According to intelligence platform Security Alliance, the cybercriminals behind the NPM (Node Package Manager) attack have managed to steal less than $50 in cryptocurrency so far.

How the attack unfolded

After breaching the NPM account of Josh Goldberg, a well-known open-source maintainer known as “Qix,” the attack specifically targeted Ethereum and Solana wallets, Security Alliance reported. The attackers injected malware into popular JavaScript libraries already downloaded by over a billion users.

Despite the scale of the attack, the proceeds were meager. Security Alliance identified the Ethereum address “0xFc4a48” as the only malicious address used so far in the operation.

Security researcher Samczsun of SEAL commented:

“You compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.”

The expert compared the situation to “finding the keycard to Fort Knox and using it as a bookmark”.

Loot details

Initially, the attack yielded just five cents in Ether (ETH), later rising to about $20 in the following hours. Data from Etherscan shows that the malicious address also received several memecoins, including Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA).

Technical mechanism

The attack affected key packages such as chalk, strip-ansi, and color-convert – small utilities deeply embedded in the dependency trees of countless projects. Even developers who hadn’t installed them directly may have been exposed.

The malware used in the attack appears to be a crypto-clipper, a type of malicious software that replaces wallet addresses during transactions in order to divert funds.

Several wallet providers confirmed they were not compromised. Ledger and MetaMask declared their platforms safe, citing “multiple layers of defense” against such attacks.

Phantom Wallet also confirmed it does not use vulnerable versions of the compromised packages, while Uniswap clarified that none of its applications are at risk. Other platforms and wallets such as Aerodrome, Aqua, BitBox02, Bitcoin Keeper, Blast, Blockstream Jade, Blue Wallet, Bull Bitcoin Wallet, Coldcard, Cove Wallet, Electrum, Foundation Devices, Nunchuk, Revoke.cash, Seedsigner, Sparrow, Specter, Trezor and Wasabi Wallet confirmed they were unaffected.

Confirmed unaffected NPM attack:@covewallet @nunchuk_io @AquaBitcoin @Blockstream @SparrowWallet @wasabiwallet @COLDCARDwallet @SpecterWallet @ElectrumWallet @FOUNDATIONdvcs @selfcustodykrux @SeedSigner @bitcoinKeeper_
Will add others below in the thread as I'm informed of…

— BTC Sessions 😎 (@BTCsessions) September 9, 2025

Post-attack recommendations

DefiLlama’s pseudonymous founder, 0xngmi, specified that only projects updated after the infected NPM package was published could be at risk. However, even in those cases, users would still need to manually approve the malicious transaction for it to have any effect.

“If you use a hardware wallet, pay attention to every transaction before signing and you’re safe,” said Charles Guillemet, CTO of Ledger.

As a precautionary measure, several experts recommend temporarily avoiding the use of crypto websites until developers have fully cleaned up the compromised packages.

Previous Post

Bitcoin treasury companies in trouble: NYDIG forecasts market turbulence

Next Post

Kazakhstan aims for a strategic cryptocurrency reserve by 2026

Latest News

Stratum V2: Antpool, Foundry, F2Pool e altri entrano nel Working Group
Bitcoin

Stratum V2: Antpool, Foundry, F2Pool and others join the Working Group

by Newsroom
May 8, 2026
0

Seven of the leading Bitcoin mining players join the working group to accelerate adoption of the Stratum V2 protocol.

Read moreDetails
Block Inc: guidance rivista al rialzo dopo Q1 solido, perdita Bitcoin da $173 milioni
Bitcoin

Block Inc: guidance raised after solid Q1, $173 million Bitcoin loss

by Newsroom
May 8, 2026
0

Jack Dorsey's company records a $173 million unrealized loss on its Bitcoin treasury, but raises 2026 forecasts following positive quarterly...

Read moreDetails
IREN: Nvidia entra nel capitale con warrant da 30 milioni di azioni
Bitcoin

IREN: Nvidia takes stake with 30 million share warrants

by Newsroom
May 8, 2026
0

The strategic partnership between IREN and Nvidia for AI infrastructure expansion sent the stock surging more than 25% in after-hours...

Read moreDetails
GameStop: l’offerta da $56 miliardi per eBay incontra il muro del credito
Bitcoin

GameStop: $56 billion bid for eBay hits credit wall

by Newsroom
May 8, 2026
0

The TD Securities financing letter requires the resulting company to maintain an investment-grade credit profile, a condition Moody's considers hard...

Read moreDetails
Germania: Klingbeil vuole eliminare l’esenzione fiscale dei digital asset nel 2027
Bitcoin

Germany: Klingbeil wants to eliminate digital asset tax exemption in 2027

by Newsroom
May 7, 2026
0

Finance Minister Lars Klingbeil has included in the 2027 budget a plan to tax digital assets at 25% regardless of...

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.