Bitcoin Forum
August 27, 2026, 06:42:00 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Wallet security alert: NPM Developer hacked  (Read 92 times)
EL MOHA (OP)
Hero Member
*****
Offline

Activity: 1246
Merit: 504



View Profile
September 08, 2025, 07:17:09 PM
Merited by Dzwaafu11 (2), Localhostspeed (2), Charles-Tim (1), SmartGold01 (1)
 #1


Many of us might have been seeing this circulating on X.

In simple term this is an attack or say hack into one of the most trusted NPM developers account, this Node Package Manager is the biggest host for JavaScript Packages. So it was found out that through phishing this hackers injected a malicious code into the packages which are  capable of compromising many applications including wallet extensions most especially those hot wallets, in fact there is reports that it has been downloaded over billion times already. It can simply affect all chains and isn’t selective.
This does actually steals data but as an interceptor it can interact with affect apps and even changing things automatically.

What is your business with this;

Becareful with the kind of transactions you make and as usual check through transactions details before finally submitting it because this is the regular copy and paste address attack but it has the ability to change an address to another address if the application used is compromised.

This again calls for the use of cold wallet because it is reported that the attack is capable of getting info from wallet APIs which could lead to seedphrase exposure for online wallets.

This attacks also shows that no matter your knowledge you should extra careful still be a highly skilled developer like this was gotten through phishing attack from emails, so we all should be careful.

This tells us to start embracing cold storage more

Amphenomenon
Hero Member
*****
Offline

Activity: 1358
Merit: 967


Hope Jeremiah 17vs7


View Profile WWW
September 08, 2025, 09:10:23 PM
Merited by Mia Chloe (1)
 #2

A friend shared this on his Whatsapp status

This is another proof why dev as to be cautious of the API/packages they use, constantly following up on any random update added in order to avoid max scale attack of such next time. I think many dev has overlooked this area which is highly important for dev teams, this wasn't just found in a single version, https://github.com/chalk/chalk/issues/656


You can run the following to check if you have the malware in your dependency tree:

Code:
rg -uu --max-columns=80 --glob '*.js' _0x112fa8 

Requires ripgrep:

Code:
brew install rg

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
promise444c5
Legendary
*
Offline

Activity: 1120
Merit: 1113


All things are numbers


View Profile WWW
September 08, 2025, 10:02:25 PM
Merited by Charles-Tim (2), Mia Chloe (1)
 #3

Josh Junon (Qix-) is the developer, he confirmed he’s been pwned this afternoon and the list of the affected packages versions were :
Code:

ansi-styles@6.2.2
debug@4.4.2
chalk@5.6.1
supports-color@10.2.1
strip-ansi@7.1.1
ansi-regex@6.2.1
wrap-ansi@9.0.1
color-convert@3.1.1
color-name@2.0.1
is-arrayish@0.3.3
slice-ansi@7.1.1
color@5.0.1
color-string@2.1.1
simple-swizzle@0.2.3
supports-hyperlinks@4.1.1
has-ansi@6.0.1
chalk-template@1.1.1
backslash@0.2.1


https://github.com/debug-js/debug/issues/1005#issuecomment-3266868187

It’s not like it’s been downloaded  a billion times
Quote
this Node Package Manager is the biggest host for JavaScript Packages. So it was found out that through phishing this hackers injected a malicious code into the packages which are  capable of compromising many applications including wallet extensions most especially those hot wallets, in fact there is reports that it has been downloaded over billion times already.
It wasn’t the npm registry server that was hacked entirely, it was a popular and trusted dev, this dev has some couple of popular NPM packages, which if the weekly downloads is accumulated then it’s upto Billion downloads/per week so technically with the time of publish there’s possibility that downloads could be upto/ almost  that amount..  which is huge.
The attacker actually went for the popular repos since they have more downloads..more update is on the link I shared above anyway.

DPHOR
Sr. Member
****
Offline

Activity: 826
Merit: 384



View Profile
September 08, 2025, 10:09:40 PM
 #4

This one serious oo, like I no know wetin this hacker them self dey worry about like this. Is it not better for them to use their skills into something more productive than lurking around hacking people's accounts and wallets?
Omo e dey surprise me oo.
Anyway thanks for the information at least everyone should pay close Attention to this your updates.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!