Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

May 14, 2026

Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

May 14, 2026

Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

May 14, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

    May 14, 2026

    ZachXBT Names Teen Behind $19 Million Crypto Theft Who Flaunted It On Instagram

    May 14, 2026

    Analyst Says No Reason for Bitcoin Reversal, Sees BTC Approaching Next Resistance Levels – Here Are His Targets

    May 14, 2026

    70% of long-term holders are in profit as the bitcoin floor hardens

    May 13, 2026

    Bitcoin, Ethereum and XRP Price Analysis: What’s Coming Next?

    May 13, 2026

    Wells Fargo Boosts Ethereum ETF Holdings in Q1

    May 13, 2026

    Why Market Experts Are Still Predicting A Rise Above $10,000

    May 13, 2026

    Bitmine ETH Holdings Cross 5.2 Million—CEO Announces New Phase For Crypto Markets

    May 12, 2026

    XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

    May 14, 2026

    Bitcoin Just Entered A Deceptive Territory, Here’s What You Should Know

    May 14, 2026

    XRP Ledger Hits Record High In 10K+ Wallets: Santiment

    May 13, 2026

    Mysterious Bitcoin Whale Transfers $40B After Years Of Silence

    May 13, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026

    Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

    May 14, 2026

    Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

    May 14, 2026

    XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

    May 14, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

    May 14, 2026

    UBOX Taps ClawWorks to Accelerate Independent AI Agent Economics

    May 14, 2026

    UXLINK And Origins Network Partner To Power Scalable AI-Driven Web3 Applications Using Decentralized Computing

    May 13, 2026

    WheelX.fi Expands Cross-Chain Liquidity Access Through KiteAI Integration

    May 13, 2026

    Ripple Shares DPRK Threat Data on Fraud Domains, Wallets, Campaigns

    May 5, 2026

    Digital Asset Security Moves Beyond Keys as Bitgo Adds 5-Layer Checks

    May 1, 2026

    Defillama Confirms April 2026 as Crypto’s Most-Hacked Month With 30 Incidents

    May 1, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026

    Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

    May 14, 2026

    Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

    May 14, 2026

    XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

    May 14, 2026
  • Web 3
    1. Gaming
    2. View All

    NUMINE Joins Outer Ring MMO for the Expansion of Web3 Gaming Experiences

    May 13, 2026

    GMatrixs And MiniverseCore Join Forces To Unlock Web3 Gaming Experience With Cross-Chain DApp, DeFi Applications

    May 11, 2026

    The Identity Crisis of 2026: NFTs, AI Agents and Trust on the Agentic Web

    May 11, 2026

    DTCC’s May 2026 Tokenization Announcement Explained: What It Means for U.S. Securities and Real-World Assets

    May 11, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026

    Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

    May 14, 2026

    Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

    May 14, 2026

    XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

    May 14, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026

    Michael Saylor Says the Transparency Act in the US Congress Will Positively Impact Bitcoin! Here Are the Details

    May 14, 2026

    Consensys Urges SEC to Exempt Self-Custody Wallets, Citing Regulatory Gap for 99% of Tokens

    May 14, 2026

    Three men charged in US over crypto wrench attack spree

    May 13, 2026

    Tether launches decentralized local AI using Isaac Asimov’s Psychohistory straight out of Foundation

    May 11, 2026

    Has Donald Trump been a net positive for Bitcoin or created an unbreakable partisan divide?

    May 10, 2026

    BlackRock looks to sidestep Clarity yield issues, filing for two new tokenized money market funds

    May 10, 2026

    Cardano’s Charles Hoskinson says the future of crypto wallets will be inside iPhones and Androids

    May 8, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026

    Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

    May 14, 2026

    Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

    May 14, 2026

    XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

    May 14, 2026
  • Analysis

    Trump’s CEO-filled China visit can decide whether Bitcoin’s $80,000 risk rally survives this week

    May 14, 2026

    Wall Street is buying XRP while Binance traders keep betting against it

    May 13, 2026

    Is a Drop Below $1 Coming Next?

    May 13, 2026

    UB Price Breakout Enters Discovery Phase

    May 13, 2026

    Billions Network Rally Accelerates After Binance Futures Launch

    May 13, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    Coinbase went down for over 5 hours after missing earnings. Bulls still see a path to $300 billion by 2030

    May 8, 2026

    Coinbase cuts 14% of staff as Armstrong ties cost reset to AI and market volatility

    May 6, 2026

    Bitcoin is still in charge

    May 3, 2026

    CLARITY Act stablecoin fight shifts from yield to who captures digital-dollar economics

    April 29, 2026

    What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

    May 14, 2026

    Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

    May 14, 2026

    Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

    May 14, 2026

    XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

    May 14, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Open Source Community Thwarts Massive npm Supply Chain Attack
Open Source Community Thwarts Massive npm Supply Chain Attack
Security and Privacy

Open Source Community Thwarts Massive npm Supply Chain Attack

September 9, 2025No Comments5 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A potential npm supply chain disaster was averted in record time after attackers took over a verified developer’s credentials.

On September 8, Josh Junon, a developer with over 1800 GitHub contributions in the last year, confirmed on Bluesky his npm account was compromised. Junon had been alerted by other users that his account had started posting packages with backdoors to all popular packages the developer was involved in.

The developer, commonly known as ‘qix,’ said he received an email to reset his two-factor authentication (2FA) that looked “very legitimate,” but that was malicious.

He added that it only involved his npm account and that he was in contact with NPM to resolve the issue.

Compromised npm Packages

The compromised ‘qix’ npm account published malicious versions for dozens of packages Junon was involved in.

These included some npm packages for high-volume JavaScript projects:

  • chalk (approximately 300 million weekly downloads)
  • strip-ansi (approximately 261 million weekly downloads)
  • color-convert (approximately 193 million weekly downloads)
  • color-name (approximately 191 million weekly downloads)
  • error-ex (approximately 47 million weekly downloads)
  • simple-swizzle approximately 26 million weekly downloads)
  • has-ansi (approximately 12 million weekly downloads)

The payload implanted in the malicious packages is a crypto-clipper that steals funds by swapping wallet addresses in network requests and directly hijacking crypto transactions.

Crypto-Stealer Attack Chain Explained

This sophisticated malware targets cryptocurrency users through two main attack vectors.

First, it checks if a wallet extension (like MetaMask) is present. If not, it launches a passive address-swapping attack, intercepting all web traffic by hijacking the browser’s fetch and XMLHttpRequest functions. The malware then replaces legitimate crypto addresses with attacker-controlled ones, using the Levenshtein distance algorithm to pick the most visually similar address, making the swap nearly undetectable to the naked eye.

See also  Dark Web Drugs Vendor Forfeits $150m After Guilty Plea

If a wallet is detected, the malware escalates to active transaction hijacking. It intercepts outgoing transactions (e.g., eth_sendTransaction) and modifies the recipient address in memory before the user signs it. The victim sees a legitimate-looking confirmation screen, but if they don’t verify the address carefully their funds are sent straight to the attacker.

The attack chain is stealthy and automated, exploiting both human perception (via address spoofing) and technical vulnerabilities (via wallet API manipulation). By compromising a trusted npm package, the malware spreads silently, infecting websites and stealing funds without raising immediate suspicion.

One of the primary Ethereum addresses used in the attack is 0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976. People can see its activity live on Ethereum-scanning website Etherscan to traxksome of the stolen funds

A GitHub Gist listing all affected wallets has also been created.

An Averted Crisis that Should Be “Celebrated”

Four hours after Junon confirmed the compromise, he shared a message from NPM saying that all impacted package versions had been taken down.

While many people started calling this hack the “biggest supply chain attack in history” on social media, many voices have challenged this narrative.

Josh Bressers, VP of security at Anchore, said on LinkedIn: “Here’s the thing nobody seems to be talking about. This all lasted for only a few hours. It’s amazing how fast open source can respond to things like this. Everyone works together. Information can be shared. The number of people now working on this isn’t just larger than your security team, it’s larger than your company.”

Katie Paxton-Fear, an ethical hacker who recently started working as a staff security advocate at Semgrep, published a video on LinkedIn emphasizing that a major crisis has been averted.

See also  UN Links North Korea to $281m Crypto Exchange Heist

“Obviously, any security breach is bad, but this is not the major security breach that people are making it out to be,” she said.

She highlighted that the estimated total loss only amounted to $20, thanks primarily to the rapid response of the open source community.

“The malware was noticed and people started talking about it on GitHub within only 15 minutes of the malicious packages going live. Some of the packages were taken down by maintainers just one hour after the compromise happened, and the rest of them by NPM within two hours,” she explained.

According to Arda Büyükkaya, a senior cyber threat intelligence analyst at EclecticIQ, the attacker’s crypto address shows $66.52.

Nevertheless, Paxton-Fear argued that this incident is “a win that shows that the open source model works and that should be celebrated.”

In another LinkedIn post, Melissa Bischoping, the director for endpoint security research at Tanium, went further: “If you’re panicking about that NPM thing, please don’t. There’s a virtually 0 chance you’re impacted by this, and you should not burn your teams by having them pick apart every corner of your infrastructure for evidence of these compromised packages.”

She continued: “These were up for a couple of hours on a Monday morning (US time) The chances of them being downloaded and shipped into your software in that window of time are very, very small – nearly 0. Of all of the things I think you should have your team pull late nights for, this isn’t one of them.”

How to Mitigate This Threat

However, those who still think they may be affected can take immediate action to block vulnerable dependencies.

See also  Neo X goes live on LayerZero, connecting to 170+ chain ecosystem

According to Jan-David Stärk, a team lead and software engineer at Hansalog, to force-safe versions across an entire project, developers can use overrides in their package.json, by adding the following to pin trusted versions of the compromised packages:

{

  “name”: “your-project”,

  “version”: “1.0.0”,

  “overrides”: {

    “chalk”: “5.3.0”,

    “strip-ansi”: “7.1.0”,

    “color-convert”: “2.0.1”,

    “color-name”: “1.1.4”,

    “is-core-module”: “2.13.1”,

    “error-ex”: “1.3.2”,

    “has-ansi”: “5.0.1”

  }

}

Then, developers should clean their project by deleting node_modules and package-lock.json, then run npm install to generate a fresh, secure lockfile.

This will ensure that no malicious versions remain in their dependency tree.

Attack Chain community Massive npm open source Supply Thwarts
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Three men charged in US over crypto wrench attack spree

May 13, 2026

Nabox Wallet Integrates ShareX ($SHARE) – Revolutionizing the Web3 Sharing Economy via BNB Chain

May 12, 2026

Is ETH Preparing for a Massive Breakout in May?

May 11, 2026

Bitcoin (BTC) mining pools with 75% of hashrate back open standard for block construction

May 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Interview with Kyle Jenke on the Future of On-Chain Finance

January 19, 2026

SUI Slides 3.4% as $2.60 Support Snaps on 180% Volume Surge

October 29, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

What Is the CLARITY Act? The US Crypto Bill That Could Reshape Digital Asset Regulation This Week

May 14, 2026

Stables Taps T-0 Network as Asia’s 60% Stablecoin Payment Share Tests USDT Rails

May 14, 2026

Exodus slashes Bitcoin holdings by 50% in Q1 2026 – Is BTC’s volatility why?

May 14, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.