• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Major Phishing Attack Compromises Node.js Developer, Injects Malicious Code into Popular Packages
Share
  • bitcoinBitcoin(BTC)$115,031.00
  • ethereumEthereum(ETH)$4,539.59
  • rippleXRP(XRP)$3.04
  • tetherTether(USDT)$1.00
  • solanaSolana(SOL)$240.09
  • binancecoinBNB(BNB)$907.86
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.263466
  • staked-etherLido Staked Ether(STETH)$4,533.55
  • tronTRON(TRX)$0.348576
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

Major Phishing Attack Compromises Node.js Developer, Injects Malicious Code into Popular Packages

News Desk
Last updated: September 9, 2025 1:39 pm
News Desk
Published: September 9, 2025
Share
8f48b5546dc438c0a126363acee73ba576ac3b1b 1024x768
Credits: www.coindesk.com

A recent phishing attack has raised alarms within the software development community as it compromised one of Node.js’s most notable package maintainers, known as “qix.” This incident unfolded on Monday when qix fell victim to an email masquerading as support from npmjs[.]help, a domain previously linked to a Russian server. The email led to a counterfeit two-factor authentication page hosted on BunnyCDN, where qix unwittingly submitted sensitive information including usernames, passwords, and 2FA codes.

With newfound access, the attacker proceeded to republish several packages, notably chalk and debug-js, injecting malicious payloads into them. These packages, which are integral components in numerous development projects, are downloaded billions of times each week, turning the breach into one of the most significant software supply-chain attacks seen in recent history.

The injected code was relatively straightforward yet effective, manipulating Ethereum transactions by checking for the presence of window.ethereum. When detected, it redirected key transaction functions—such as approval and transfer—to a wallet address controlled by the attacker. Moreover, for users of Solana, the malware disrupted transfers by altering recipient addresses with invalid strings.

Despite the extensive reach of this attack, which potentially affected countless developers and their applications, its financial impact was surprisingly minimal. On-chain analysis indicated that the attacker garnered only a few cents in Ether and approximately $20 worth of a less common memecoin. The Security Alliance’s report highlighted this stark contrast, asserting that while the attack’s scale was vast, the monetary gain was negligible.

On the defensive front, major players such as the popular browser wallet MetaMask reassured their users by declaring they were not affected by the npm supply chain breach. MetaMask employs rigorous security measures, including code version locks, a combination of manual and automated checks, and progressive release updates. Additionally, they utilize advanced tools like “LavaMoat,” which prevents the execution of malicious code, and “Blockaid,” which swiftly identifies compromised wallet addresses.

In light of this incident, Ledger’s CTO, Charles Guillemet, emphasized the need for heightened vigilance, noting that the attack’s payload had merged into packages with extensive download histories intended to silently manipulate wallet addresses in user transactions.

This incident is another reminder of the vulnerabilities present in software supply chains, coming on the heels of other alarming discoveries, such as a recent warning from ReversingLabs regarding npm packages that utilized Ethereum smart contracts to obscure malware links. As the cybersecurity landscape continues to evolve, developers and maintainers are urged to enhance their protective measures to guard against similar threats in the future.

Dominari Holdings Applauds American Bitcoin’s Nasdaq Debut, Highlights Strategic Stake
Bitget Token Surge Sparks Renewed Investor Interest in Crypto Market
Large-Scale Supply Chain Attack Targets NPM Packages, Risks Crypto Transactions
XRP, Avalanche, and Dogecoin Set for Potential Rallies as Crypto Market Braces for ETF Decisions
Public Petition Urges UK Government to Establish Pro-Innovation Blockchain Strategy Following Coinbase Support
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Pudgy Penguins PENGU 1 scaled PENGU Coin Gains Traction as Pudgy Party Mobile Game Launches on iOS and Android
Next Article urlhttps3A2F2Fassets.apnews.com2F512F542F17e92699bfe8e2a1a9dac87f24372Fcb21a5e0e40b41ca9c83 France Faces Political Turmoil as Prime Minister Bayrou Resigns After Confidence Vote
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
ffce425a45676a27ed21df0ae403fc3ecb6d5a16 700x430
Stellar’s XLM Faces Volatility Amid Rising Competition in Payments Sector
shutterstock 1866715063
Coinbase Soars as Cryptocurrency Exchange Moves Toward Green Initiatives and Carbon Market Integration
68c4158557d362d375e809e0
Goldman Sachs Identifies Risks That Could Pressure Stock Prices Despite Optimism
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Stocks
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?