Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Compromised files replace npm packages with a combined 2 billion weekly downloads

Tech Wavo by Tech Wavo
September 10, 2025
in Computers
0




  • Over a dozen popular npm packages were compromised in a phishing-based supply chain attack
  • The malware targeted crypto users by hijacking wallet addresses during transactions
  • Some called it the most widespread npm compromise to date, affecting 2 billion weekly downloads

More than a dozen npm packages with two billion downloads a week were compromised in a supply chain attack that targeted cryptocurrency users.

Researchers at Aikido Security spotted a maintainer account Qix (real name Josh Junon) publishing malicious updates. In less than an hour, multiple versions were uploaded, and soon after Junon himself confirmed the attack and apologized for the mess,

“Yep, I’ve been pwned. 2FA reset email, looked very legitimate,” Junon wrote on Bluesky, confirming that the breach started with a convincing phishing email.


You may like

Targeting crypto users

“Only NPM affected, I’ve sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up,” he stressed, showing how even the most careful people can get hit if they lower their guard.

According to The Hacker News, this is the list of 20 compromised packages, cumulatively counting 2 billion weekly downloads:

  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]

At the same time, CyberInsider described it as “the most widespread supply chain compromise in the history of the npm ecosystem.”

The malware being distributed through the packages apparently targeted cryptocurrency users. It is designed to intercept crypto transactions by swapping out the destination wallet address with one controlled by the attackers. Ethereum, Solana, Bitcoin, Tron, Litecoin, and Bitcoin Cash seem to be the chains targeted in this campaign.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Via The Hacker News

You might also like

Previous Post

AirPods Pro 3 offer live translation and heart rate monitoring

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Compromised files replace npm packages with a combined 2 billion weekly downloads

by Tech Wavo
September 10, 2025
0
Leaked Intel database reveals how a simple login flaw exposed 270,000 employees and shattered confidence in corporate digital defenses
Computers

Over a dozen popular npm packages were compromised in a phishing-based supply chain attackThe malware targeted crypto users by hijacking...

Read more

AirPods Pro 3 offer live translation and heart rate monitoring

by Tech Wavo
September 10, 2025
0
AirPods Pro 3 offer live translation and heart rate monitoring
Computers

Today's Apple event wasn't just about iPhones and smartwatches. The company also announced the long-anticipated refresh of the AirPods Pro...

Read more

Nikon Zr review: cinema cameras just got a major new player

by Tech Wavo
September 10, 2025
0
Nikon Zr review: cinema cameras just got a major new player
Computers

Why you can trust TechRadar We spend hours testing every product or service we review, so you can be sure...

Read more

Apple Watch SE 3 has an S10 chip and always-on display

by Tech Wavo
September 10, 2025
0
Apple Watch SE 3 has an S10 chip and always-on display
Computers

After three years, the Apple Watch SE is finally getting a refresh. The company showed off the Apple Watch SE...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock