Massive Supply Chain Attack Hits Crypto Ecosystem via NPM
StarPlatinum
A massive supply chain attack just hit the JavaScript ecosystem.
18 core NPM packages were hacked, including chalk, strip ansi and debug.
These libraries have over 2 billion weekly downloads.
Here’s what happened, how it affects crypto and how to stay safe 🧵


On September 8th, the NPM account of developer Qix- was hacked through a phishing email:
support@npmjshelp
Attackers pushed malicious updates to 18 widely used packages, including:
chalk
strip-ansi
color-convert
debug
error-ex
ansi-styles

The phishing domain was registered just three days before the attack.
Once they got access, they moved fast, malicious versions were live within hours.
These libraries are foundational.
They sit deep inside most web apps, which is why the impact is so dangerous.

The malware is a crypto clipper built to steal funds.
It works in two ways:
• Passive address swap: silently replaces wallet addresses inside dApps.
• Active hijack: intercepts live transactions before signing and swaps the destination address.

This makes it almost invisible.
The malware uses the Levenshtein algorithm to replace your wallet address with one that looks visually similar.
You think you are sending to your own wallet.
But you’re sending to theirs.

The attacker’s main Ethereum wallet:
0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976
Backup wallets found:
0xa29eEfB3f21Dc8FA8bce065Db4f4354AA683c024
0x40C351B989113646bc4e9Dfe66AE66D24fE6Da7B
0x30F895a2C66030795131FB66CBaD6a1f91461731
So far, no funds have been moved

How this started:
Developers first noticed strange build errors like fetch is not defined.
When they inspected the code, they found heavy obfuscation hiding functions like checkethereumw
A clear sign this was targeting crypto.

If you build or use apps connected to crypto:
• Use a hardware wallet and carefully check addresses before signing
• Pin exact package versions in package.json
• Run npm ci instead of npm install
• Rotate your GitHub and NPM keys now
This time, the community caught it fast.
But the fact that 2 billion weekly downloads were compromised shows how fragile our systems are.
For more information please check this post:
https://x.com/P3b7_/status/1965094840959410230
A sweeping narrative ties Jane Street to India’s expiry-day options case, alleged 10AM Bitcoin sell patterns, Terra’s collapse, and ETF plumbing. While none prove misconduct, critics argue a common structure: move spot, monetize derivatives, keep execution opaque.
Bull Theory/2 days ago
A controversial narrative links Jane Street, ETF mechanics, and Bitcoin’s price behavior, pointing to lawsuit allegations, 10AM volatility patterns, and derivative hedging dynamics. The discussion raises broader questions about liquidity, structure, and price discovery.
Justin Bechler/3 days ago
A new federal lawsuit alleges Jane Street exploited non-public information tied to Terraform’s liquidity defenses, accelerating UST’s depeg and the Terra collapse. The firm denies the claims. The case may reignite debates on structure, design, and regulation.
Diana/4 days ago
Mean reversion and on-chain models sit at levels historically linked to bottom formation after capitulation. Realized losses reached record USD values, while deviations from anchor models remain extreme. Price pain may be fading; patience remains key.
Checkmate/4 days ago
Bitcoin didn’t fail as an asset — it matured into an ETF-driven trade. As institutional ownership rose, correlation with tech risk intensified. Short-term pressure reflects holder structure shifts, not thesis collapse.
Eric Jackson/5 days ago
This weekly report frames Bitcoin within a six-stage bear market model. With BTC in Stage 4, price stagnation drives exhaustion and weak-hand selling while liquidity builds. The harshest mechanical drop may be over, but fear and capitulation likely remain ahead.
Doctor Profit/6 days ago
Hot feeds
A trader profits $448K by monitoring #Binance's new listings!
2024.12.13 17:37:29
A smart #AI coin trader made $17.6M on $GOAT, $ai16z, $Fartcoin,$arc.
2025.01.05 16:05:18
When Elon Musk tweeted about Moltbook, the meme coin MOLT experienced a short-term 30% price surge, hitting a new all-time high of $114 million.
2026.01.31 18:37:29
Last week, funds have flowed into #Bitcoin, #Ethereum, and #Hyperliquid.
2024.12.16 14:48:36
A $PEPE whale that had been dormant for 600 days transferred all 2.1T $PEPE($52M) to a new address.
2024.12.14 10:35:27
A sniper earned 2,277 $ETH ($8.3M) trading $SHIRO within 18 hours!
2024.12.03 23:09:08
MoreHot Articles

How did I turn $1,000 into $30,000 with smart money?
2024.12.09

10 promising AI Agent cryptos
2024.12.05

The 30-Year-Old Entrepreneur Behind Virtual, a Multi-Million Dollar AI Agent Society
2025.01.22

10 smart traders specializing in MEMEcoin trading on Solana
2024.12.09

A trader lost $73.9K trading memecoins in just 3 minutes — a lesson for us all!
2024.12.13

What is $SPORE? Let us take you through the on-chain records to show you how it works.
2024.12.25
