Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
What's Hot

Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

October 3, 2026

U.S. labor market weakens – Why this October could be different for Bitcoin

October 3, 2026

SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

October 3, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    U.S. labor market weakens – Why this October could be different for Bitcoin

    October 3, 2026

    Wall Street giant BNY discusses infrastructure tie-up with Kraken parent Payward

    October 3, 2026

    IMF Praises El Salvador But Tries To Scale Back Bitcoin Use

    October 3, 2026

    Bitcoin ETFs record $102M inflows – Why $85K matters for BTC now

    October 3, 2026

    Ethereum Price Holds $2,600 as Futures Activity Dominates

    October 3, 2026

    SEC Approves 3x Leveraged Bitcoin Ether & Other ETPs for Listing

    October 3, 2026

    Ethereum: Why ETH faces October reversal risk after 70% Q3 rally

    October 3, 2026

    Why Did Blast Decide to Wind Down Its L2?

    October 2, 2026

    Visa Says Business Payments Now Drive 17% Of Stablecoin-Linked Card Volume

    October 3, 2026

    Fidelity exec’s new 60/20/20 portfolio makes room for crypto – Here’s why

    October 3, 2026

    Can NEAR crypto rebound? THESE metrics could decide what’s next

    October 3, 2026

    Polymath And CineCity Explore Regulated Tokenized Film Investment Platform

    October 3, 2026

    Thinking Cat Gains Momentum After CASHCAT’s Breakout

    August 12, 2026

    What Tokens Could He Target?

    July 30, 2026

    The Next Meme Coin Winner Could Be Determined by Incentives, Not Memes

    July 30, 2026

    Why Is BOME’s Price Up Today? Finally, Capital Rotating to the Meme Coins?

    July 28, 2026

    Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

    October 3, 2026

    U.S. labor market weakens – Why this October could be different for Bitcoin

    October 3, 2026

    SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

    October 3, 2026

    Ethereum Price Holds $2,600 as Futures Activity Dominates

    October 3, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

    October 3, 2026

    OpenZeppelin and T-REX Network Introduce new Framework for Regulated Token Eligibility and Recovery

    October 3, 2026

    GMX Sponsors Arbitrum’s Open House Singapore as Buildathon

    October 3, 2026

    Ceteris Introduces Tokenized Stocks via Crypto Neobanks

    October 3, 2026

    Masked Robbers Threaten Pregnant Wife in UK Crypto Home Attack

    October 3, 2026

    Bitcoin Lightning Nodes Targeted as Core Lightning Sounds Alarm

    October 2, 2026

    The $459,000 Bot Hacker Was a Customer First, Researchers Say

    October 2, 2026

    Metamask Pulls Validators as Meager ETH Theft Sounds Big Alarm

    October 2, 2026

    Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

    October 3, 2026

    U.S. labor market weakens – Why this October could be different for Bitcoin

    October 3, 2026

    SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

    October 3, 2026

    Ethereum Price Holds $2,600 as Futures Activity Dominates

    October 3, 2026
  • Web 3
    1. Gaming
    2. View All

    Top 12 NFT games every player should know about in August 2026

    September 22, 2026

    GameShame Studios founder details Raijin Protocol’s roadmap in NeoPod’s sixth AMA

    September 22, 2026

    Proof of Play to shut down after blockchain gaming thesis falls short

    September 22, 2026

    How BC.GAME is turning players into stakeholders

    September 22, 2026

    Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

    October 3, 2026

    U.S. labor market weakens – Why this October could be different for Bitcoin

    October 3, 2026

    SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

    October 3, 2026

    Ethereum Price Holds $2,600 as Futures Activity Dominates

    October 3, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

    October 3, 2026

    FBI Top 10 Fugitive Sanctioned by OFAC for Crypto Laundering

    October 3, 2026

    CFTC wins $31M Fundsz fraud order as crypto scam losses mount worldwide

    October 3, 2026

    583 Companies Go Public in 18 Months, Says SEC Chairman

    October 3, 2026

    Stablecoin issuers have replaced 40% of China’s lost US Treasury demand

    October 3, 2026

    Bitcoin’s $113,000 case strengthens as US regulators push 9 crypto actions

    October 2, 2026

    Bitget restores $300M fund after absorbing $388M security breach

    October 2, 2026

    Ripple’s biggest institutional bet may now be Brazil

    October 1, 2026

    Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

    October 3, 2026

    U.S. labor market weakens – Why this October could be different for Bitcoin

    October 3, 2026

    SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

    October 3, 2026

    Ethereum Price Holds $2,600 as Futures Activity Dominates

    October 3, 2026
  • Analysis

    Cardano Faces Bearish Signals as Futures Demand Cools and Whales Sell

    October 3, 2026

    WLD Price Nears $0.70 Resistance — 3 On-Chain Signals Reveal the Next Move

    October 3, 2026

    Plunging GPU prices threaten AI hosts, and new hedges step in

    October 3, 2026

    Ethereum Price Faces $2,800 Wall Again — Are Whales Selling or Accumulating ETH?

    October 3, 2026

    Bull Market Targets for BTC, ETH, SOL, and XRP

    October 3, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Robinhood Chain? The Ethereum Layer-2 Network for Tokenized Stocks

    July 12, 2026

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    Coinbase completes Deribit migration, ends INTX trading

    October 2, 2026

    Binance Funding Account ends direct crypto deposits

    October 1, 2026

    Coinbase just completed its US derivatives stack but its biggest bet still sits outside it

    September 30, 2026

    Bitget had 30 minutes to contain its hack before $290 million started moving

    September 30, 2026

    Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

    October 3, 2026

    U.S. labor market weakens – Why this October could be different for Bitcoin

    October 3, 2026

    SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

    October 3, 2026

    Ethereum Price Holds $2,600 as Futures Activity Dominates

    October 3, 2026
  • Tools
    • Market Overview
    • Exchange Tool
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Open Source Community Thwarts Massive npm Supply Chain Attack
Open Source Community Thwarts Massive npm Supply Chain Attack
Security and Privacy

Open Source Community Thwarts Massive npm Supply Chain Attack

September 9, 2025No Comments5 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A potential npm supply chain disaster was averted in record time after attackers took over a verified developer’s credentials.

On September 8, Josh Junon, a developer with over 1800 GitHub contributions in the last year, confirmed on Bluesky his npm account was compromised. Junon had been alerted by other users that his account had started posting packages with backdoors to all popular packages the developer was involved in.

The developer, commonly known as ‘qix,’ said he received an email to reset his two-factor authentication (2FA) that looked “very legitimate,” but that was malicious.

He added that it only involved his npm account and that he was in contact with NPM to resolve the issue.

Compromised npm Packages

The compromised ‘qix’ npm account published malicious versions for dozens of packages Junon was involved in.

These included some npm packages for high-volume JavaScript projects:

  • chalk (approximately 300 million weekly downloads)
  • strip-ansi (approximately 261 million weekly downloads)
  • color-convert (approximately 193 million weekly downloads)
  • color-name (approximately 191 million weekly downloads)
  • error-ex (approximately 47 million weekly downloads)
  • simple-swizzle approximately 26 million weekly downloads)
  • has-ansi (approximately 12 million weekly downloads)

The payload implanted in the malicious packages is a crypto-clipper that steals funds by swapping wallet addresses in network requests and directly hijacking crypto transactions.

Crypto-Stealer Attack Chain Explained

This sophisticated malware targets cryptocurrency users through two main attack vectors.

First, it checks if a wallet extension (like MetaMask) is present. If not, it launches a passive address-swapping attack, intercepting all web traffic by hijacking the browser’s fetch and XMLHttpRequest functions. The malware then replaces legitimate crypto addresses with attacker-controlled ones, using the Levenshtein distance algorithm to pick the most visually similar address, making the swap nearly undetectable to the naked eye.

See also  A New Strain of Malware Is Terrorizing Docker Hosts

If a wallet is detected, the malware escalates to active transaction hijacking. It intercepts outgoing transactions (e.g., eth_sendTransaction) and modifies the recipient address in memory before the user signs it. The victim sees a legitimate-looking confirmation screen, but if they don’t verify the address carefully their funds are sent straight to the attacker.

The attack chain is stealthy and automated, exploiting both human perception (via address spoofing) and technical vulnerabilities (via wallet API manipulation). By compromising a trusted npm package, the malware spreads silently, infecting websites and stealing funds without raising immediate suspicion.

One of the primary Ethereum addresses used in the attack is 0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976. People can see its activity live on Ethereum-scanning website Etherscan to traxksome of the stolen funds

A GitHub Gist listing all affected wallets has also been created.

An Averted Crisis that Should Be “Celebrated”

Four hours after Junon confirmed the compromise, he shared a message from NPM saying that all impacted package versions had been taken down.

While many people started calling this hack the “biggest supply chain attack in history” on social media, many voices have challenged this narrative.

Josh Bressers, VP of security at Anchore, said on LinkedIn: “Here’s the thing nobody seems to be talking about. This all lasted for only a few hours. It’s amazing how fast open source can respond to things like this. Everyone works together. Information can be shared. The number of people now working on this isn’t just larger than your security team, it’s larger than your company.”

Katie Paxton-Fear, an ethical hacker who recently started working as a staff security advocate at Semgrep, published a video on LinkedIn emphasizing that a major crisis has been averted.

See also  Hackers Steal $5m+ From Blockchain Platform Solana

“Obviously, any security breach is bad, but this is not the major security breach that people are making it out to be,” she said.

She highlighted that the estimated total loss only amounted to $20, thanks primarily to the rapid response of the open source community.

“The malware was noticed and people started talking about it on GitHub within only 15 minutes of the malicious packages going live. Some of the packages were taken down by maintainers just one hour after the compromise happened, and the rest of them by NPM within two hours,” she explained.

According to Arda Büyükkaya, a senior cyber threat intelligence analyst at EclecticIQ, the attacker’s crypto address shows $66.52.

Nevertheless, Paxton-Fear argued that this incident is “a win that shows that the open source model works and that should be celebrated.”

In another LinkedIn post, Melissa Bischoping, the director for endpoint security research at Tanium, went further: “If you’re panicking about that NPM thing, please don’t. There’s a virtually 0 chance you’re impacted by this, and you should not burn your teams by having them pick apart every corner of your infrastructure for evidence of these compromised packages.”

She continued: “These were up for a couple of hours on a Monday morning (US time) The chances of them being downloaded and shipped into your software in that window of time are very, very small – nearly 0. Of all of the things I think you should have your team pull late nights for, this isn’t one of them.”

How to Mitigate This Threat

However, those who still think they may be affected can take immediate action to block vulnerable dependencies.

See also  SEO Poisoning Targets Chinese Users with Fake Software Sites

According to Jan-David Stärk, a team lead and software engineer at Hansalog, to force-safe versions across an entire project, developers can use overrides in their package.json, by adding the following to pin trusted versions of the compromised packages:

{

  “name”: “your-project”,

  “version”: “1.0.0”,

  “overrides”: {

    “chalk”: “5.3.0”,

    “strip-ansi”: “7.1.0”,

    “color-convert”: “2.0.1”,

    “color-name”: “1.1.4”,

    “is-core-module”: “2.13.1”,

    “error-ex”: “1.3.2”,

    “has-ansi”: “5.0.1”

  }

}

Then, developers should clean their project by deleting node_modules and package-lock.json, then run npm install to generate a fresh, secure lockfile.

This will ensure that no malicious versions remain in their dependency tree.

Attack Chain community Massive npm open source Supply Thwarts
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

GMX Sponsors Arbitrum’s Open House Singapore as Buildathon

October 3, 2026

Masked Robbers Threaten Pregnant Wife in UK Crypto Home Attack

October 3, 2026

Bitcoin Lightning Nodes Targeted as Core Lightning Sounds Alarm

October 2, 2026

Moca Chain Mainnet Goes Live With Identity Credentials for Businesses and AI Agents

October 2, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

AscendEX and Attarius Network Join Forces to Boost Web3 Gaming NFTs

January 24, 2026

Deutsche Bank-backed Taurus and Blockdaemon team up to power institutional staking services

February 14, 2026

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Zano Says Over $200M in Illicit Tokens Led to 30-Day Blockchain Rewind

October 3, 2026

U.S. labor market weakens – Why this October could be different for Bitcoin

October 3, 2026

SEC charges Meyer Global with SpaceX pre-IPO fraud as private-market bets move on-chain

October 3, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.