The NPM (node packet manager) account of developer ‘qix’ was compromised, allowing hackers to publish malicious versions of his packages.
The attackers published malicious versions of dozens of extremely popular JavaScript packages, including fundamental utilities. The hack was massive in scope since the affected packages have over 1 billion combined weekly downloads.
This attack on the software supply chain specifically targets the JavaScript/Node.js ecosystem.
NPM Supply Chain Attack
Popular dev qix fell victim to phishing. Malicious code injected into npm packages now hijacks crypto transactions at signing.
Attack method:
• Hooks wallet functions (request/send)
• Swaps recipient addresses in ETH/SOL transactions
• Replaces… pic.twitter.com/Jn9H4HWP8v
— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) September 8, 2025
Crypto Clipper Malware
The malicious code was a “crypto-clipper” designed to steal cryptocurrency by swapping wallet addresses in network requests
We współpracy z: https://cryptopotato.com/crypto-stealing-malware-infiltrates-core-javascript-libraries-used-by-millions/