Tuesday, August 11, 2026
  • Login
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
CRYPTO MARKETCAP
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

by SB Crypto Guru News
September 8, 2025
in Crypto Updates
Reading Time: 7 mins read
0 0
A A
0


A major supply-chain attack has infiltrated widely
used JavaScript packages, potentially putting billions of dollars in crypto at
risk. Charles Guillemet, chief technology officer at hardware wallet maker
Ledger, warned that hackers have compromised a reputable developer’s Node
Package Manager (NPM) account to push malicious code into packages downloaded
more than a billion times.

The injected malware is designed to quietly swap
cryptocurrency wallet addresses in transactions, meaning users could
unknowingly send funds directly to attackers.

“There’s a large-scale supply chain attack in progress: the
NPM account of a reputable developer has been compromised,” Guillemet explained. “The affected
packages have already been downloaded over 1 billion times, meaning the entire
JavaScript ecosystem may be at risk.”

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.

The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

Supply Chain Attack Hits Deep Into Developer Ecosystem

NPM is a core tool in JavaScript development, widely
used to integrate external packages into applications. When a developer’s
account is compromised, attackers can slip malware into packages that
developers then unknowingly deploy in decentralized applications or software
wallets.

Security researchers have warned that software wallet users
are particularly vulnerable, while hardware wallets remain largely protected. According to Oxngmi, founder of DefiLlama, the code
does not automatically drain wallets.

Explanation of the current npm hack

In any website that uses this hacked dependency, it gives a chance to the hacker to inject malicious code, so for example when you click a “swap” button on a website, the code might replace the tx sent to your wallet with a tx sending money to…

— 0xngmi (@0xngmi) September 8, 2025

Developers who pin dependencies to older, safe
versions may avoid exposure, but users cannot easily verify which sites are
safe. Experts recommend avoiding crypto transactions until affected packages
are cleaned up.

Phishing Emails and Account Takeover

The breach reportedly began with phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term
emails sent to NPM
maintainers, claiming their accounts would be locked unless they “updated”
two-factor authentication by Sept. 10.

The fake site captured credentials, giving attackers
control of developer accounts. From there, malicious updates were pushed to
packages downloaded billions of times.

Related: Regulator Claims 9,000+ Clients’ Data Hit Dark Web in Security Breach

Charlie Eriksen of Aikido Security said the attack
operates “at multiple layers: altering content shown on websites, tampering
with API calls, and manipulating what users’ apps believe they are signing.”

ATTACK UPDATE: A massive supply-chain compromise has affected packages with over 2 billion weekly downloads, targeting *CRYPTO*

Here’s how it works 👇

1) Injects itself into the browser

Hooks core functions like fetch, XMLHttpRequest, and wallet APIs (window.ethereum, Solana,…

— Aikido Security (@AikidoSecurity) September 8, 2025

Developers and users have been urged to review dependencies
and delay crypto transactions until the packages are verified as safe. The
incident highlighted the risks inherent in widely used open-source software and
the potential for supply-chain attacks to affect billions of users.

A major supply-chain attack has infiltrated widely
used JavaScript packages, potentially putting billions of dollars in crypto at
risk. Charles Guillemet, chief technology officer at hardware wallet maker
Ledger, warned that hackers have compromised a reputable developer’s Node
Package Manager (NPM) account to push malicious code into packages downloaded
more than a billion times.

The injected malware is designed to quietly swap
cryptocurrency wallet addresses in transactions, meaning users could
unknowingly send funds directly to attackers.

“There’s a large-scale supply chain attack in progress: the
NPM account of a reputable developer has been compromised,” Guillemet explained. “The affected
packages have already been downloaded over 1 billion times, meaning the entire
JavaScript ecosystem may be at risk.”

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.

The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

Supply Chain Attack Hits Deep Into Developer Ecosystem

NPM is a core tool in JavaScript development, widely
used to integrate external packages into applications. When a developer’s
account is compromised, attackers can slip malware into packages that
developers then unknowingly deploy in decentralized applications or software
wallets.

Security researchers have warned that software wallet users
are particularly vulnerable, while hardware wallets remain largely protected. According to Oxngmi, founder of DefiLlama, the code
does not automatically drain wallets.

Explanation of the current npm hack

In any website that uses this hacked dependency, it gives a chance to the hacker to inject malicious code, so for example when you click a “swap” button on a website, the code might replace the tx sent to your wallet with a tx sending money to…

— 0xngmi (@0xngmi) September 8, 2025

Developers who pin dependencies to older, safe
versions may avoid exposure, but users cannot easily verify which sites are
safe. Experts recommend avoiding crypto transactions until affected packages
are cleaned up.

Phishing Emails and Account Takeover

The breach reportedly began with phishing
Phishing

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno

Phishing is a form of cyber-attack in which fake websites, emails, and text messages are used to elicit personal data. The most common targets in this assault are passwords, private cryptocurrency keys, and credit card details.Phishers disguise themselves as reputable businesses and other types of entities. In certain instances, reputable government organizations or authorities are impersonated in order to collect this data.Because phishing relies on psychological manipulation rather than techno
Read this Term
emails sent to NPM
maintainers, claiming their accounts would be locked unless they “updated”
two-factor authentication by Sept. 10.

The fake site captured credentials, giving attackers
control of developer accounts. From there, malicious updates were pushed to
packages downloaded billions of times.

Related: Regulator Claims 9,000+ Clients’ Data Hit Dark Web in Security Breach

Charlie Eriksen of Aikido Security said the attack
operates “at multiple layers: altering content shown on websites, tampering
with API calls, and manipulating what users’ apps believe they are signing.”

ATTACK UPDATE: A massive supply-chain compromise has affected packages with over 2 billion weekly downloads, targeting *CRYPTO*

Here’s how it works 👇

1) Injects itself into the browser

Hooks core functions like fetch, XMLHttpRequest, and wallet APIs (window.ethereum, Solana,…

— Aikido Security (@AikidoSecurity) September 8, 2025

Developers and users have been urged to review dependencies
and delay crypto transactions until the packages are verified as safe. The
incident highlighted the risks inherent in widely used open-source software and
the potential for supply-chain attacks to affect billions of users.





Source link

Tags: accountsaffectingattackBitcoin NewsCryptoCrypto NewsCrypto UpdatesDownloadsexploithackersJavaScriptLatest News on CryptoMassivereportedlySB Crypto Guru News
Previous Post

Luxor, Canaan Team up on Financing for 5,000+ Avalon A15 Pro Miners

Next Post

London’s National Gallery receives record-breaking donations for new wing—and will start collecting contemporary art – The Art Newspaper

Related Posts

Former Irish PM Bertie Ahern’s Crypto Charity Shutting Down

Former Irish PM Bertie Ahern’s Crypto Charity Shutting Down

by SB Crypto Guru News
August 11, 2026
0

Key TakeawaysBertie Ahern’s AB Foundation applied to dissolve after never trading following its 2025 launch.The collapse highlights rising regulatory scrutiny...

TRON’s USDT Hits .9B as Q2 Transfers Reach .1T and Fees Jump 15.9%

TRON’s USDT Hits $87.9B as Q2 Transfers Reach $2.1T and Fees Jump 15.9%

by SB Crypto Guru News
August 11, 2026
0

Key Takeaways:The total stablecoin supply on TRON hit a new high of $89.2B, spearheaded by USDT.The network facilitated USDT transacting...

North Korea’s Kimsuky Turns AI Into a Crypto Hacking Weapon

North Korea’s Kimsuky Turns AI Into a Crypto Hacking Weapon

by SB Crypto Guru News
August 10, 2026
0

Key TakeawaysKimsuky tested 3 local AI platforms as North Korea expands its cyber capabilities.Genians says Kimsuky has used AI-generated phishing...

Ruble Stablecoin A7A5 Has Processed Close to 0 Billion Since February 2025 Launch

Ruble Stablecoin A7A5 Has Processed Close to $140 Billion Since February 2025 Launch

by SB Crypto Guru News
August 10, 2026
0

Ruble-denominated stablecoin A7A5 has processed close to $140 billion in turnover since its February 2025 launch, Pyotr Fradkov, CEO of...

North Korean Hackers Deploy 3 Local AI Systems to Supercharge Crypto Attacks

North Korean Hackers Deploy 3 Local AI Systems to Supercharge Crypto Attacks

by SB Crypto Guru News
August 10, 2026
0

Key Takeaways:Kimsuky was using Ollama, GPT4All and Msty, three local LLM environments.Crypto, financial and investment targets are being scammed using...

Load More
Next Post
London’s National Gallery receives record-breaking donations for new wing—and will start collecting contemporary art – The Art Newspaper

London’s National Gallery receives record-breaking donations for new wing—and will start collecting contemporary art - The Art Newspaper

This Simple Practice Did More for My Business Than Any Productivity Hack

This Simple Practice Did More for My Business Than Any Productivity Hack

  • Trending
  • Comments
  • Latest
AI Giants Unleash 4 Frontier Models in 3 Weeks as the Race Enters Overdrive

AI Giants Unleash 4 Frontier Models in 3 Weeks as the Race Enters Overdrive

July 26, 2026
Saylor and Strategy Officially Back CLARITY Act for US Crypto

Saylor and Strategy Officially Back CLARITY Act for US Crypto

July 31, 2026
How to Track Your Brand’s AI Visiblity in 2026 

How to Track Your Brand’s AI Visiblity in 2026 

August 1, 2026
The .2 billion options wall came down, and this time Bitcoin actually moved

The $1.2 billion options wall came down, and this time Bitcoin actually moved

July 21, 2026
SUI Prints Bullish Flag Pattern As Traders Watch For Breakout

SUI Prints Bullish Flag Pattern As Traders Watch For Breakout

July 18, 2026
Ironwood Goes Live as Zcash Locks Down Orchard and Forces a .8B Migration

Ironwood Goes Live as Zcash Locks Down Orchard and Forces a $1.8B Migration

July 28, 2026
Australia Shuts Down 96 Crypto ATMs After Cryptolink Faces AML Reporting Crackdown

Australia Shuts Down 96 Crypto ATMs After Cryptolink Faces AML Reporting Crackdown

0
Nvidia Nears 0 Billion Deal With Wall Street’s Biggest Firms

Nvidia Nears $500 Billion Deal With Wall Street’s Biggest Firms

0
Jupiter Lend v2 Links Lending Returns to Trading Fees

Jupiter Lend v2 Links Lending Returns to Trading Fees

0
Comment | This year’s Venice Biennale is filled with thought-provoking reminders of past art disputes – The Art Newspaper

Comment | This year’s Venice Biennale is filled with thought-provoking reminders of past art disputes – The Art Newspaper

0
BTCPay Server Offers 3 BTC Bounty

BTCPay Server Offers 3 BTC Bounty

0
OCEAN Pledges BTC Refunds After Chain-Split Error

OCEAN Pledges BTC Refunds After Chain-Split Error

0
Nvidia Nears 0 Billion Deal With Wall Street’s Biggest Firms

Nvidia Nears $500 Billion Deal With Wall Street’s Biggest Firms

August 11, 2026
Comment | This year’s Venice Biennale is filled with thought-provoking reminders of past art disputes – The Art Newspaper

Comment | This year’s Venice Biennale is filled with thought-provoking reminders of past art disputes – The Art Newspaper

August 11, 2026
On-chain data shows  million at risk as Tether’s Alloy shutdown deadline boils down to 5 forgotten gold vaults

On-chain data shows $50 million at risk as Tether’s Alloy shutdown deadline boils down to 5 forgotten gold vaults

August 11, 2026
Jupiter Lend v2 Links Lending Returns to Trading Fees

Jupiter Lend v2 Links Lending Returns to Trading Fees

August 11, 2026
Former Irish PM Bertie Ahern’s Crypto Charity Shutting Down

Former Irish PM Bertie Ahern’s Crypto Charity Shutting Down

August 11, 2026
Yen Rescue Could Fuel a Bitcoin Rally

Yen Rescue Could Fuel a Bitcoin Rally

August 11, 2026
Facebook Twitter LinkedIn Tumblr RSS
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at SB Crypto Guru News.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.