Lookonchain APP

App Store

Massive Supply Chain Attack Hits Crypto Ecosystem via NPM

StarPlatinum
/4 days ago
A massive supply chain attack has compromised 18 foundational NPM packages, affecting billions of weekly downloads. Hackers pushed malicious code designed to be a crypto clipper, which silently swaps wallet addresses to steal funds. The incident was quickly caught, but it highlights a critical vulnerability in the core infrastructure of the crypto ecosystem.

A massive supply chain attack just hit the JavaScript ecosystem.

18 core NPM packages were hacked, including chalk, strip ansi and debug.

These libraries have over 2 billion weekly downloads.

Here’s what happened, how it affects crypto and how to stay safe 🧵

On September 8th, the NPM account of developer Qix- was hacked through a phishing email:

support@npmjshelp

Attackers pushed malicious updates to 18 widely used packages, including:

chalk
strip-ansi
color-convert
debug
error-ex
ansi-styles

The phishing domain was registered just three days before the attack.

Once they got access, they moved fast, malicious versions were live within hours.

These libraries are foundational.

They sit deep inside most web apps, which is why the impact is so dangerous.

The malware is a crypto clipper built to steal funds.

It works in two ways:

• Passive address swap: silently replaces wallet addresses inside dApps.

• Active hijack: intercepts live transactions before signing and swaps the destination address.

This makes it almost invisible.

The malware uses the Levenshtein algorithm to replace your wallet address with one that looks visually similar.

You think you are sending to your own wallet.

But you’re sending to theirs.

The attacker’s main Ethereum wallet:
0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976

Backup wallets found:

0xa29eEfB3f21Dc8FA8bce065Db4f4354AA683c024
0x40C351B989113646bc4e9Dfe66AE66D24fE6Da7B
0x30F895a2C66030795131FB66CBaD6a1f91461731

So far, no funds have been moved

How this started:

Developers first noticed strange build errors like fetch is not defined.

When they inspected the code, they found heavy obfuscation hiding functions like checkethereumw

A clear sign this was targeting crypto.

If you build or use apps connected to crypto:

• Use a hardware wallet and carefully check addresses before signing
• Pin exact package versions in package.json
• Run npm ci instead of npm install
• Rotate your GitHub and NPM keys now

This time, the community caught it fast.

But the fact that 2 billion weekly downloads were compromised shows how fragile our systems are.

For more information please check this post:
https://x.com/P3b7_/status/1965094840959410230
 

Relevant content
Arthur Hayes: Net worth and on-chain holdings

Arthur Hayes is best known as the former CEO of BitMex. However, he is also an influential and provocative essayist and crypto commentator who was convicted, then pardoned, for violating the Bank Secrecy Act

Arkham/23 hours ago

The Altcoin Season Playbook: My Top Picks for a Massive Rally

The author predicts that a new altseason is starting as money rotates into Ethereum and large-cap altcoins. To prepare, the author shares a personal portfolio of top picks across the DeFi, AI, and memecoin narratives, including $PEPE, $SOL, and $ENA. The strategy is to position now before the rally, with a plan to scale out of positions at new all-time highs.

Mister Crypto/2 days ago

Recession Warning: Why a Bitcoin Drop to $90K is Inevitable

This article argues that a recessionary crash is inevitable, based on the historic inversion and normalization of the yield curve. Despite a longer-than-usual delay, the author maintains a firm bearish outlook and predicts Bitcoin will drop to the $90K–$94K range. The author outlines a clear plan to sell spot holdings and take short positions in anticipation of this coming move.

Doctor Profit/3 days ago

Fed Rate Cuts Could Spark Altseason. Here Are 5 Alts to Watch.

The article argues that upcoming Federal Reserve rate cuts will inject trillions in liquidity, triggering a new macro cycle for crypto. This shift in capital from traditional assets to riskier ones is expected to ignite a massive altseason. The author identifies this as the perfect setup and lists several low-cap altcoins with high potential for explosive growth.

Pepesso/5 days ago

The Downfall of a Crypto Influencer: The Story of Gainzy

A look into the controversial history of crypto influencer Gainzy reveals a pattern of profiting from shilling and insider moves, not trading. The story alleges his involvement in an ICO rug pull and secret token sales as a sponsored streamer. Now on PumpFun, Gainzy is accused of crashing his own memecoin live on stream, with a new wallet profiting from his followers losses.

StarPlatinum/2025.09.05

Why Passive Crypto Investing Fails (and What to Do Instead)

The article argues that passive, buy-and-hold crypto investing is flawed, as it offers lower returns with far greater risk than the stock market. Instead, it suggests that crypto’s true advantage lies in active trading strategies. A simple long/short strategy, for example, demonstrated vastly superior risk-adjusted returns, proving that to succeed in the volatile crypto market, you must be an active participant, not a passive one.

Pavel | Robuxio/2025.09.03