Hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries, targeting crypto wallets. Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X: The $50 figure was, however, bumped up from 5 cents a few hours earlier, suggesting the potential damage may still be unfolding.The 5 cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.Related: Pokémon cards will soon have their ‘Polymarket moment’ — BitwiseThe breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.Read more Hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries, targeting crypto wallets. Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X: The $50 figure was, however, bumped up from 5 cents a few hours earlier, suggesting the potential damage may still be unfolding.The 5 cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.Related: Pokémon cards will soon have their ‘Polymarket moment’ — BitwiseThe breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.Read more

Largest npm attack in crypto history stole less than $50: SEAL

2025/09/09 06:31

Hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries, targeting crypto wallets.

Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.

Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.

Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X:

The $50 figure was, however, bumped up from 5 cents a few hours earlier, suggesting the potential damage may still be unfolding.

The 5 cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.

Related: Pokémon cards will soon have their ‘Polymarket moment’ — Bitwise

The breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.

Read more

Market Opportunity
Ethervista Logo
Ethervista Price(VISTA)
$3.032
$3.032$3.032
-5.16%
USD
Ethervista (VISTA) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Liquidations Surge 108% to $665 Million as Bearish Sentiment Dominates

Liquidations Surge 108% to $665 Million as Bearish Sentiment Dominates

The cryptocurrency market experienced a brutal 24-hour period, with liquidations surging 108% to reach $665 million. The spike in forced position closures reflects the violent price action that has characterized recent trading sessions, catching leveraged traders on both sides of the market.
Share
MEXC NEWS2025/12/16 19:30
Tajikistan Imposes Harsh Penalties for Illegal Crypto Mining Linked to Power Theft

Tajikistan Imposes Harsh Penalties for Illegal Crypto Mining Linked to Power Theft

Tajikistan has enacted legislation criminalizing unauthorized cryptocurrency mining operations connected to electricity theft. Violators face fines reaching approximately $8,200 and prison terms of up to 8 years, signaling the government's serious stance against illicit mining activities draining the national power grid.
Share
MEXC NEWS2025/12/16 19:32
Stablecoins Are Booming — And The Fed Thinks They Could Cut Rates

Stablecoins Are Booming — And The Fed Thinks They Could Cut Rates

The post Stablecoins Are Booming — And The Fed Thinks They Could Cut Rates appeared on BitcoinEthereumNews.com. Stablecoins Are Booming — And The Fed Thinks They Could Cut Rates | Bitcoinist.com Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Christian, a journalist and editor with leadership roles in Philippine and Canadian media, is fueled by his love for writing and cryptocurrency. Off-screen, he’s a cook and cinephile who’s constantly intrigued by the size of the universe. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/stablecoins-are-booming-and-the-fed-thinks-they-could-cut-rates/
Share
BitcoinEthereumNews2025/11/11 05:05