• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: 18 JavaScript Packages Compromised in Largest Supply Chain Hack to Steal Cryptocurrency
Share
  • bitcoinBitcoin(BTC)$114,982.00
  • ethereumEthereum(ETH)$4,510.24
  • rippleXRP(XRP)$3.05
  • tetherTether(USDT)$1.00
  • solanaSolana(SOL)$238.06
  • binancecoinBNB(BNB)$907.84
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.260124
  • staked-etherLido Staked Ether(STETH)$4,505.45
  • tronTRON(TRX)$0.348151
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

18 JavaScript Packages Compromised in Largest Supply Chain Hack to Steal Cryptocurrency

News Desk
Last updated: September 9, 2025 5:25 pm
News Desk
Published: September 9, 2025
Share
wtxYoWaQRG3RnuMspcogx7
Credits: www.tomshardware.com

In a shocking revelation, a significant breach involving 18 JavaScript packages has been uncovered, marking what is described as the largest supply chain hack in history. With over 2 billion weekly downloads, these packages were compromised with malicious code aimed at stealing cryptocurrency.

The attack, perpetrated by an unknown threat actor, saw the modification of the packages to execute code on users’ browsers. This code silently intercepted cryptocurrency and Web3 activities, manipulating wallet interactions and rewiring payment destinations to divert funds to accounts controlled by the attackers, all without any visible signs for users.

These vulnerable packages are distributed through npm, the package manager and repository for the Node.js ecosystem, demonstrating their widespread use and reliance in modern software development. The scale of the breach raises critical questions about the security state of software development today, especially as the malicious code targeted popular cryptocurrencies such as Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash.

The extent of the breach is still unclear, given the sheer volume of downloads these packages command weekly. The risk is further exacerbated by software build systems that routinely fetch dependencies, reinforcing the need for vigilance among organizations that utilize these packages in their software stacks.

The breach was made possible due to a social engineering tactic aimed at the maintainer of the affected packages, who goes by the handle “bad-at-computer” on Bluesky. They received an email that appeared to be a legitimate two-factor authentication reset request from a fraudulent domain, which led to the successful compromise of their account. This incident highlights a growing concern within the tech community: malicious actors can exploit relatively simple methods to carry out complex attacks.

This situation is not unprecedented; past incidents have demonstrated the vulnerability of software package maintainers across various ecosystems, including JavaScript, Python, Ruby, and Java. Notably, the 2016 left-pad incident showcased the fragility of software dependencies when just 11 lines of code were deleted, disrupting vast portions of the internet.

Despite ongoing efforts to bolster security through measures like Software Bills of Materials (SBOMs) and mandatory two-factor authentication for package maintainers, the results of this attack underscore the inadequacies in existing security protocols. As the industry continues to grapple with these challenges, the question remains: will the next incident cause even more significant damage than a cryptocurrency theft, or will sufficient solutions emerge to prevent these attacks altogether?

The implications of this breach extend beyond just a financial loss; it reflects broader issues in the software development landscape. The tech community must address these vulnerabilities to avert future breaches that could lead to even more disastrous consequences.

Coinbase CEO Mandates 50% AI-Generated Code by 2025, Employees Face Job Risk Without Tool Adoption
Angel Studios Debuts on NYSE with Strong Investor Support for Values-Based Entertainment Strategy
Bitget COO Vugar Usi Zade Talks Blockchain Education at TEDx Forbes Park
MEI Pharma Rebrands as Lite Strategy, Embraces Cryptocurrency with $100 Million in Litecoin
Soft U.S. Inflation Data Boosts Crypto Prices
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 61ca13c0c2114cbbbf4c82ceeba91b7a Lion Group Holding to Convert Entire Solana and Sui Holdings into HYPE Tokens
Next Article RLUSD CB VivoPower’s EV Subsidiary Adopts Ripple’s RLUSD for Payments, Excludes XRP
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
96aa31f9 385a 4f5d 8cd4 e02cbce8f612 1140x641
Meridian Residents Targeted by Cryptocurrency Scam Featuring Disturbing Letters
gettyimages 2149260829 1200x675 128554e
Bitcoin’s Valuation Compared to Gold Suggests Significant Upside Potential
68c3a3406733d4c8ef48fb7a 68c3a2b0f2ffb9ecbbd42b8c lastImage
Ethereum’s Institutional Surge: A New Era of Opportunity and Transformation
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • DeFi
  • Blockchain
  • Stocks
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?