Lookonchain APP

App Store

Massive Supply Chain Attack Hits Crypto Ecosystem via NPM

StarPlatinum
/2025.09.10 00:57:34
A massive supply chain attack has compromised 18 foundational NPM packages, affecting billions of weekly downloads. Hackers pushed malicious code designed to be a crypto clipper, which silently swaps wallet addresses to steal funds. The incident was quickly caught, but it highlights a critical vulnerability in the core infrastructure of the crypto ecosystem.

A massive supply chain attack just hit the JavaScript ecosystem.

18 core NPM packages were hacked, including chalk, strip ansi and debug.

These libraries have over 2 billion weekly downloads.

Here’s what happened, how it affects crypto and how to stay safe 🧵

On September 8th, the NPM account of developer Qix- was hacked through a phishing email:

support@npmjshelp

Attackers pushed malicious updates to 18 widely used packages, including:

chalk
strip-ansi
color-convert
debug
error-ex
ansi-styles

The phishing domain was registered just three days before the attack.

Once they got access, they moved fast, malicious versions were live within hours.

These libraries are foundational.

They sit deep inside most web apps, which is why the impact is so dangerous.

The malware is a crypto clipper built to steal funds.

It works in two ways:

• Passive address swap: silently replaces wallet addresses inside dApps.

• Active hijack: intercepts live transactions before signing and swaps the destination address.

This makes it almost invisible.

The malware uses the Levenshtein algorithm to replace your wallet address with one that looks visually similar.

You think you are sending to your own wallet.

But you’re sending to theirs.

The attacker’s main Ethereum wallet:
0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976

Backup wallets found:

0xa29eEfB3f21Dc8FA8bce065Db4f4354AA683c024
0x40C351B989113646bc4e9Dfe66AE66D24fE6Da7B
0x30F895a2C66030795131FB66CBaD6a1f91461731

So far, no funds have been moved

How this started:

Developers first noticed strange build errors like fetch is not defined.

When they inspected the code, they found heavy obfuscation hiding functions like checkethereumw

A clear sign this was targeting crypto.

If you build or use apps connected to crypto:

• Use a hardware wallet and carefully check addresses before signing
• Pin exact package versions in package.json
• Run npm ci instead of npm install
• Rotate your GitHub and NPM keys now

This time, the community caught it fast.

But the fact that 2 billion weekly downloads were compromised shows how fragile our systems are.

For more information please check this post:
https://x.com/P3b7_/status/1965094840959410230
 

Relevant content
Jane Street Under the Microscope: Liquidity, Derivatives, and Market Disruption Claims

A sweeping narrative ties Jane Street to India’s expiry-day options case, alleged 10AM Bitcoin sell patterns, Terra’s collapse, and ETF plumbing. While none prove misconduct, critics argue a common structure: move spot, monetize derivatives, keep execution opaque.

Bull Theory/2 days ago

Jane Street, ETFs, and Bitcoin: Allegations, Market Structure, and the 10AM Debate

A controversial narrative links Jane Street, ETF mechanics, and Bitcoin’s price behavior, pointing to lawsuit allegations, 10AM volatility patterns, and derivative hedging dynamics. The discussion raises broader questions about liquidity, structure, and price discovery.

Justin Bechler/3 days ago

Jane Street and Terra: Revisiting the UST Collapse Through New Allegations

A new federal lawsuit alleges Jane Street exploited non-public information tied to Terraform’s liquidity defenses, accelerating UST’s depeg and the Terra collapse. The firm denies the claims. The case may reignite debates on structure, design, and regulation.

Diana/4 days ago

Bitcoin at Extremes: Oversold Signals and the Bottom Formation Thesis

Mean reversion and on-chain models sit at levels historically linked to bottom formation after capitulation. Realized losses reached record USD values, while deviations from anchor models remain extreme. Price pain may be fading; patience remains key.

Checkmate/4 days ago

Bitcoin’s ETF Era: Correlation, Holder Structure, and the Next Capital Wave

Bitcoin didn’t fail as an asset — it matured into an ETF-driven trade. As institutional ownership rose, correlation with tech risk intensified. Short-term pressure reflects holder structure shifts, not thesis collapse.

Eric Jackson/5 days ago

Bitcoin Bear Market Psychology: Stage 4, Liquidity Traps, and the Path to Capitulation

This weekly report frames Bitcoin within a six-stage bear market model. With BTC in Stage 4, price stagnation drives exhaustion and weak-hand selling while liquidity builds. The harshest mechanical drop may be over, but fear and capitulation likely remain ahead.

Doctor Profit/6 days ago