• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: 18 JavaScript Packages Compromised in Largest Supply Chain Hack to Steal Cryptocurrency
Share
  • bitcoinBitcoin(BTC)$71,273.00
  • ethereumEthereum(ETH)$2,165.81
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$646.95
  • rippleXRP(XRP)$1.41
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$91.85
  • tronTRON(TRX)$0.314146
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02
  • dogecoinDogecoin(DOGE)$0.095934
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

18 JavaScript Packages Compromised in Largest Supply Chain Hack to Steal Cryptocurrency

News Desk
Last updated: September 9, 2025 5:25 pm
News Desk
Published: September 9, 2025
Share
wtxYoWaQRG3RnuMspcogx7
Credits: www.tomshardware.com

In a shocking revelation, a significant breach involving 18 JavaScript packages has been uncovered, marking what is described as the largest supply chain hack in history. With over 2 billion weekly downloads, these packages were compromised with malicious code aimed at stealing cryptocurrency.

The attack, perpetrated by an unknown threat actor, saw the modification of the packages to execute code on users’ browsers. This code silently intercepted cryptocurrency and Web3 activities, manipulating wallet interactions and rewiring payment destinations to divert funds to accounts controlled by the attackers, all without any visible signs for users.

These vulnerable packages are distributed through npm, the package manager and repository for the Node.js ecosystem, demonstrating their widespread use and reliance in modern software development. The scale of the breach raises critical questions about the security state of software development today, especially as the malicious code targeted popular cryptocurrencies such as Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash.

The extent of the breach is still unclear, given the sheer volume of downloads these packages command weekly. The risk is further exacerbated by software build systems that routinely fetch dependencies, reinforcing the need for vigilance among organizations that utilize these packages in their software stacks.

The breach was made possible due to a social engineering tactic aimed at the maintainer of the affected packages, who goes by the handle “bad-at-computer” on Bluesky. They received an email that appeared to be a legitimate two-factor authentication reset request from a fraudulent domain, which led to the successful compromise of their account. This incident highlights a growing concern within the tech community: malicious actors can exploit relatively simple methods to carry out complex attacks.

This situation is not unprecedented; past incidents have demonstrated the vulnerability of software package maintainers across various ecosystems, including JavaScript, Python, Ruby, and Java. Notably, the 2016 left-pad incident showcased the fragility of software dependencies when just 11 lines of code were deleted, disrupting vast portions of the internet.

Despite ongoing efforts to bolster security through measures like Software Bills of Materials (SBOMs) and mandatory two-factor authentication for package maintainers, the results of this attack underscore the inadequacies in existing security protocols. As the industry continues to grapple with these challenges, the question remains: will the next incident cause even more significant damage than a cryptocurrency theft, or will sufficient solutions emerge to prevent these attacks altogether?

The implications of this breach extend beyond just a financial loss; it reflects broader issues in the software development landscape. The tech community must address these vulnerabilities to avert future breaches that could lead to even more disastrous consequences.

Gold and silver prices decline on MCX amid profit booking and rising dollar
S&P 500 Expected to Trade Sideways After Strong Start to 2025
Iran-Driven Oil Volatility Could Derail Bitcoin Price Rally, Bloomberg’s Mike McGlone Warns
Texas Voters Approve Bigger Property Tax Breaks for Homeowners and Businesses
Indonesian Stocks Plunge Over 15% Amid MSCI Investability Warning
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 61ca13c0c2114cbbbf4c82ceeba91b7a Lion Group Holding to Convert Entire Solana and Sui Holdings into HYPE Tokens
Next Article RLUSD CB VivoPower’s EV Subsidiary Adopts Ripple’s RLUSD for Payments, Excludes XRP
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
108279148 1773776726281 gettyimages 2264943610 20090101260308 99 764834
Stocks Rise on Hopes for Resolution to Iran War; Meta Faces Legal Setbacks
usps 3
USPS to Introduce 8% Fuel Surcharge Amid Rising Oil Prices
https3A2F2Fsubstack post media.s3.amazonaws.com2Fpublic2Fimages2F2ea81bfe 9b76 4afc 889f 4f4a3
SEC Enforcement Chief Resigns Amid Allegations of Insider Trading Tied to Trump’s Announcement
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • News
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?