{
    "id": 48571,
    "date": "2025-09-09T09:55:03",
    "date_gmt": "2025-09-09T02:55:03",
    "guid": {
        "rendered": "https:\/\/hbbgroup.net\/largest-npm-attack-in-crypto-history-stole-less-than-50-seal\/"
    },
    "modified": "2025-09-09T09:55:03",
    "modified_gmt": "2025-09-09T02:55:03",
    "slug": "largest-npm-attack-in-crypto-history-stole-less-than-50-seal",
    "status": "publish",
    "type": "post",
    "link": "https:\/\/hbbgroup.net\/en_us\/largest-npm-attack-in-crypto-history-stole-less-than-50-seal\/",
    "title": {
        "rendered": "Largest NPM attack in crypto history stole less than $50: SEAL"
    },
    "content": {
        "rendered": "<div data-gtm-locator=\"articles\" data-v-43e640e6>\n<article id=\"article-214564\" data-v-43e640e6>\n<p itemprop=\"description\" data-v-43e640e6> Hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries, targeting crypto wallets. <\/p>\n<div data-v-43e640e6><picture><source media=\"(min-width: 1200px)\" ><source media=\"(min-width: 992px)\" ><source media=\"(min-width: 768px)\" ><source media=\"(min-width: 480px)\" ><img  loading=\"eager\" fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=1434\/https:\/\/s3.cointelegraph.com\/uploads\/2025-09\/01992b44-43fd-7ebb-a012-d9b06468441c\" alt=\"Largest NPM attack in crypto history stole less than $50: SEAL\"><\/picture><\/div>\n<div data-v-43e640e6>\n<div data-v-43e640e6>\n<div>\n<p>Hackers have only managed to steal  $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.<\/p>\n<p>Crypto intelligence platform Security Alliance <a href=\"https:\/\/www.securityalliance.org\/news\/2025-09-npm-supply-chain\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/www.securityalliance.org\/news\/2025-09-npm-supply-chain\">shared<\/a> the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and <a data-ct-non-breakable=\"null\" href=\"https:\/\/bsky.app\/profile\/bad-at-computer.bsky.social\/post\/3lydioq5swk2y\" rel=\"https:\/\/bsky.app\/profile\/bad-at-computer.bsky.social\/post\/3lydioq5swk2y\" target=\"https:\/\/bsky.app\/profile\/bad-at-computer.bsky.social\/post\/3lydioq5swk2y\" title=\"https:\/\/bsky.app\/profile\/bad-at-computer.bsky.social\/post\/3lydioq5swk2y\">added<\/a> malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.<\/p>\n<p>Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address \u201c0xFc4a48\u201d as what it believes to be the only malicious address so far. It <a href=\"https:\/\/x.com\/_SEAL_Org\/status\/1965142759213584812\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/_SEAL_Org\/status\/1965142759213584812\">added<\/a> on X: <\/p>\n<\/div>\n<blockquote><p>\u201dPicture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster.  You profit less than 50 USD.\u201d<\/p><\/blockquote>\n<figure><img decoding=\"async\" alt src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-09\/01992b4c-9f4b-7eda-9021-1850d037005d\" title><figcaption><em>Source: <\/em><a href=\"https:\/\/x.com\/_SEAL_Org\/status\/1965142760660562210\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/_SEAL_Org\/status\/1965142760660562210\"><em>Security Alliance<\/em><\/a><\/figcaption><\/figure>\n<p data-ct-non-breakable=\"undefined\">The $50 figure was, however, <a href=\"https:\/\/x.com\/_SEAL_Org\/status\/1965147035344273718\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/_SEAL_Org\/status\/1965147035344273718\">bumped<\/a> up from five cents a few hours earlier, suggesting the potential damage may still be unfolding.<\/p>\n<h2>ETH, memecoin among small amount of crypto stolen<\/h2>\n<div>\n<p>The five cents stolen were in Ether (<a href=\"http:\/\/cointelegraph.com\/ethereum-price\">ETH<\/a>) while another $20 worth of a memecoin was compromised, Security Alliance said. <\/p>\n<p>Etherscan <a href=\"https:\/\/etherscan.io\/address\/0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976#tokentxns\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/etherscan.io\/address\/0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976#tokentxns\">data<\/a> shows the malicious address has received Brett (<a href=\"http:\/\/cointelegraph.com\/brett-price-index\">BRETT<\/a>), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.<\/p>\n<\/div>\n<h2>Crypto projects that didn\u2019t download the NPMs still at risk<\/h2>\n<p>The breach targeted packages such as\u00a0chalk,\u00a0strip-ansi,\u00a0and\u00a0color-convert\u00a0\u2014 small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.<\/p>\n<p>The attackers appear to have planted a\u00a0crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds. <\/p>\n<div data-ct-non-breakable=\"undefined\">\n<p>Ledger chief technology officer Charles Guillemet was among many who have urged crypto users to proceed with caution when confirming onchain transactions.<\/p>\n<p>In a separate post, Ledger <a href=\"https:\/\/x.com\/Ledger\/status\/1965172338657259898\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/Ledger\/status\/1965172338657259898\">said<\/a> its devices weren\u2019t directly affected by the NPM attack.<\/p>\n<\/div>\n<h2>You won\u2019t be instantly drained, crypto founder says<\/h2>\n<div>\n<p>0xngmi, the pseudonymous founder of crypto analytics platform DeFiLlama, however <a href=\"https:\/\/x.com\/0xngmi\/status\/1965125988016087050\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/0xngmi\/status\/1965125988016087050\">said<\/a> only crypto projects that updated after the malware-infected NPM package was published may be at risk, and even then, users must approve the malicious transaction for it to work.<\/p>\n<p>Though like Guillemet, he said it may be safer to avoid using crypto websites until developers behind those platforms clean up the bad packages.<\/p>\n<\/div>\n<p type><em>This is a developing story, and further information will be added as it becomes available.<\/em><\/p>\n<p data-ct-non-breakable=\"undefined\"><em><strong>Magazine: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/magazine\/chatgpt-linked-murder-suicide-after-accidental-jailbreak-ai-eye\/\" rel target=\"_self\" title=\"https:\/\/cointelegraph.com\/magazine\/chatgpt-linked-murder-suicide-after-accidental-jailbreak-ai-eye\/\"><em><strong>\u2018Accidental jailbreaks\u2019 and ChatGPT\u2019s links to murder, suicide: AI Eye<\/strong><\/em><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\" label=\"Subscription Form: Markets Outlook\"><\/template><\/div>\n<p><img decoding=\"async\" alt src=\"https:\/\/zoa.cointelegraph.com\/pixel?postId=214564&#038;regionId=1\" data-v-43e640e6><\/p>\n<\/div>\n<\/div>",
        "protected": false
    },
    "excerpt": {
        "rendered": "<p>Hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript [&hellip;]<\/p>",
        "protected": false
    },
    "author": 1,
    "featured_media": 48572,
    "comment_status": "open",
    "ping_status": "open",
    "sticky": false,
    "template": "",
    "format": "standard",
    "meta": {
        "_acf_changed": false,
        "footnotes": ""
    },
    "categories": [
        220
    ],
    "tags": [],
    "class_list": [
        "post-48571",
        "post",
        "type-post",
        "status-publish",
        "format-standard",
        "has-post-thumbnail",
        "hentry",
        "category-tien-dien-tu"
    ],
    "acf": [],
    "_links": {
        "self": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/48571",
                "targetHints": {
                    "allow": [
                        "GET"
                    ]
                }
            }
        ],
        "collection": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts"
            }
        ],
        "about": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/types\/post"
            }
        ],
        "author": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/users\/1"
            }
        ],
        "replies": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/comments?post=48571"
            }
        ],
        "version-history": [
            {
                "count": 0,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/48571\/revisions"
            }
        ],
        "wp:featuredmedia": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media\/48572"
            }
        ],
        "wp:attachment": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media?parent=48571"
            }
        ],
        "wp:term": [
            {
                "taxonomy": "category",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/categories?post=48571"
            },
            {
                "taxonomy": "post_tag",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/tags?post=48571"
            }
        ],
        "curies": [
            {
                "name": "wp",
                "href": "https:\/\/api.w.org\/{rel}",
                "templated": true
            }
        ]
    }
}