• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: 18 JavaScript Packages Compromised in Largest Supply Chain Hack to Steal Cryptocurrency
Share
  • bitcoinBitcoin(BTC)$70,810.00
  • ethereumEthereum(ETH)$2,063.20
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$662.60
  • rippleXRP(XRP)$1.48
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$88.78
  • tronTRON(TRX)$0.273399
  • dogecoinDogecoin(DOGE)$0.099050
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

18 JavaScript Packages Compromised in Largest Supply Chain Hack to Steal Cryptocurrency

News Desk
Last updated: September 9, 2025 5:25 pm
News Desk
Published: September 9, 2025
Share
wtxYoWaQRG3RnuMspcogx7
Credits: www.tomshardware.com

In a shocking revelation, a significant breach involving 18 JavaScript packages has been uncovered, marking what is described as the largest supply chain hack in history. With over 2 billion weekly downloads, these packages were compromised with malicious code aimed at stealing cryptocurrency.

The attack, perpetrated by an unknown threat actor, saw the modification of the packages to execute code on users’ browsers. This code silently intercepted cryptocurrency and Web3 activities, manipulating wallet interactions and rewiring payment destinations to divert funds to accounts controlled by the attackers, all without any visible signs for users.

These vulnerable packages are distributed through npm, the package manager and repository for the Node.js ecosystem, demonstrating their widespread use and reliance in modern software development. The scale of the breach raises critical questions about the security state of software development today, especially as the malicious code targeted popular cryptocurrencies such as Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash.

The extent of the breach is still unclear, given the sheer volume of downloads these packages command weekly. The risk is further exacerbated by software build systems that routinely fetch dependencies, reinforcing the need for vigilance among organizations that utilize these packages in their software stacks.

The breach was made possible due to a social engineering tactic aimed at the maintainer of the affected packages, who goes by the handle “bad-at-computer” on Bluesky. They received an email that appeared to be a legitimate two-factor authentication reset request from a fraudulent domain, which led to the successful compromise of their account. This incident highlights a growing concern within the tech community: malicious actors can exploit relatively simple methods to carry out complex attacks.

This situation is not unprecedented; past incidents have demonstrated the vulnerability of software package maintainers across various ecosystems, including JavaScript, Python, Ruby, and Java. Notably, the 2016 left-pad incident showcased the fragility of software dependencies when just 11 lines of code were deleted, disrupting vast portions of the internet.

Despite ongoing efforts to bolster security through measures like Software Bills of Materials (SBOMs) and mandatory two-factor authentication for package maintainers, the results of this attack underscore the inadequacies in existing security protocols. As the industry continues to grapple with these challenges, the question remains: will the next incident cause even more significant damage than a cryptocurrency theft, or will sufficient solutions emerge to prevent these attacks altogether?

The implications of this breach extend beyond just a financial loss; it reflects broader issues in the software development landscape. The tech community must address these vulnerabilities to avert future breaches that could lead to even more disastrous consequences.

Kalshi Launches KalshiEco Hub to Drive Blockchain-Based Prediction Market Innovation
Coinbase and Upbit Announce New Altcoin Listings
Investors Debate OpenSea’s SEA Token Airdrop Criteria
Smarter Web Company Considers Acquisitions of Distressed Competitors to Boost Bitcoin Holdings
Digital asset investment products experience $1.9 billion inflow surge after Fed interest rate cut
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 61ca13c0c2114cbbbf4c82ceeba91b7a Lion Group Holding to Convert Entire Solana and Sui Holdings into HYPE Tokens
Next Article RLUSD CB VivoPower’s EV Subsidiary Adopts Ripple’s RLUSD for Payments, Excludes XRP
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
Bithumb Accidentally Sends Large Amounts of Bitcoin to Users Triggers Price Crash Amid Market Sellof
Bithumb Accidentally Distributes Large Bitcoin Amounts to Users During Promotion
GettyImages 51617028
Market Sentiment Shifts as Investors Question Value of IT and Software Amid AI Boom
120544204
Tax Season 2026 Begins: Filers May See Average Refund Increase of $1,000
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?