Skip to content
← Back to newsMassive NPM Attack Yields Less Than $50 in Crypto Theft
Crime

Massive NPM Attack Yields Less Than $50 in Crypto Theft

By ToTo BugelmanNewcomer0 rep· 9/9/2025

A large-scale supply chain attack targeting popular JavaScript software libraries on the Node Package Manager (NPM) has resulted in minimal crypto theft, amounting to less than $50. Security researchers from Security Alliance revealed that hackers compromised an NPM developer's account, injecting malware into widely used libraries downloaded over a billion times. While Ethereum and Solana wallets were specifically targeted, the immediate financial impact appears to be surprisingly low, though the full extent of the damage is still being assessed.

 

Josh Junon

 

Key Takeaways

  • A significant supply chain attack on NPM libraries has been detected.

  • Hackers injected malware into popular JavaScript packages.

  • Despite widespread potential impact, less than $50 in cryptocurrency was stolen.

  • Ethereum and Solana wallets were the primary targets.

 

The Attack Details

Security intelligence platform Security Alliance reported that attackers gained access to the NPM account of a prominent software developer. They then inserted malicious code into several JavaScript libraries, including chalk, strip-ansi, and color-convert. These libraries are deeply embedded in numerous projects, meaning even developers who did not directly install them could be exposed.

The malware deployed is identified as a crypto-clipper, designed to stealthily replace legitimate wallet addresses with the attacker's during transactions, thereby diverting funds. The compromised Ethereum wallet address, "0xFc4a48," is believed to be the sole recipient of the illicit funds so far.

 

Minimal Financial Impact, High Potential Risk

While the attackers had the potential to access millions of developer workstations, the actual crypto stolen was minimal. Initially reported as five cents, the amount later rose to approximately $50, comprising Ether (ETH) and various memecoins such as Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA). Etherscan data confirms these transactions to the malicious wallet address.

 

Security Alliance

 

Industry experts, including Ledger's CTO Charles Guillemet, have advised users to exercise caution and double-check on-chain transaction details. DeFiLlama founder 0xngmi noted that only projects updating their dependencies after the malware was introduced are at risk, and users must still approve the malicious transaction for it to succeed. However, he recommended avoiding crypto websites until the affected packages are cleaned.

This incident highlights the persistent threat of supply chain attacks in the software development ecosystem, particularly within the cryptocurrency space, even when the immediate financial losses are small.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Massive NPM Attack Yields Less Than $50 in Crypto Theft | BlockzHub