• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: npm Supply Chain Attack Averted Within Hours After Developer’s Account Compromise
Share
  • bitcoinBitcoin(BTC)$114,951.00
  • ethereumEthereum(ETH)$4,521.08
  • rippleXRP(XRP)$3.04
  • tetherTether(USDT)$1.00
  • solanaSolana(SOL)$239.63
  • binancecoinBNB(BNB)$908.50
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.262544
  • staked-etherLido Staked Ether(STETH)$4,513.50
  • tronTRON(TRX)$0.348181
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

npm Supply Chain Attack Averted Within Hours After Developer’s Account Compromise

News Desk
Last updated: September 9, 2025 7:14 pm
News Desk
Published: September 9, 2025
Share
a04b879c 3187 4d95 98f0 12a936ef385c
Credits: www.infosecurity-magazine.com

A significant security incident within the npm ecosystem was quickly resolved after a developer’s account was compromised, leading to the publication of malicious packages. On September 8, Josh Junon, a well-recognized developer with over 1,800 GitHub contributions in the past year, announced on Bluesky that his npm account had been hacked. He was alerted by other users who noticed the account was posting packages containing backdoors.

Junon, known in the developer community as ‘qix,’ explained that he received a seemingly legitimate email requesting a reset of his two-factor authentication (2FA), which turned out to be a malicious attempt to gain access. He confirmed that the breach was limited to his npm account and communicated with npm support to address the situation.

The compromised npm account released harmful versions of multiple packages that are integral to high-volume JavaScript projects, including:

  • chalk (around 300 million weekly downloads)
  • strip-ansi (approximately 261 million weekly downloads)
  • color-convert (around 193 million weekly downloads)
  • color-name (approximately 191 million weekly downloads)
  • error-ex (about 47 million weekly downloads)
  • simple-swizzle (approximately 26 million weekly downloads)
  • has-ansi (around 12 million weekly downloads)

The malicious packages contained a sophisticated crypto-clipper that stealthily siphoned funds by altering wallet addresses during network transactions. The malware operated through two primary mechanisms: passive address-swapping and active transaction hijacking. If a crypto wallet extension, such as MetaMask, was present, the malware would intercept outgoing transactions, changing the recipient address before the user could sign it. This allowed it to direct funds to the attacker instead of their intended destination.

The compromised Ethereum address linked to the attack is trackable on Etherscan, providing real-time visibility of its activities. Furthermore, a GitHub Gist has been created to list all affected wallets.

In a rapid response, npm removed all impacted package versions just four hours after the compromise was confirmed. While some observers labeled this incident as the “biggest supply chain attack in history,” others, including Josh Bressers, VP of security at Anchore, highlighted the community’s swift and effective response. Bressers noted that the incident lasted only a few hours, showcasing the strength of collaboration within the open-source community.

Katie Paxton-Fear, an ethical hacker and staff security advocate at Semgrep, shared insights indicating that while security breaches are concerning, the prompt reaction from the community minimized the risk. She revealed that the estimated financial loss was remarkably low, around $20, thanks to early detection and the rapid takedown of the malicious packages. Paxton-Fear pointed out that discussions about the issue began within a mere 15 minutes of the harmful packages being published.

To mitigate potential impacts from similar vulnerabilities, Jan-David Stärk, a team lead at a software engineering firm, recommended that developers take precautionary measures. They should pin trusted versions of the compromised packages in their project’s package.json file and refresh their dependencies to eliminate any malicious versions.

Recommendations included adding specific overrides to ensure that the project utilizes safe versions of the affected packages and cleaning up the project environment to maintain security. Such actions emphasize the importance of vigilance and proactive strategies in safeguarding the software supply chain against security threats.

Job Openings Fall to 7.18 Million in July, Below Expectations
KuCoin Partners with Vietnam Blockchain Association to Accelerate Digital Economy and Blockchain Innovation
US Dollar Under Pressure as Rate-Cut Expectations Rise Amid Weak Jobs Data
SEC’s Atkins Outlines Clear Regulations for Crypto Assets and Agentic Finance
Robot Consulting Plans $6.74 Million Investment in Ethereum to Enhance Legal Services
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article strategy bets 217m on bitcoin MicroStrategy Increases Bitcoin Holdings to 638,460 BTC with $271 Million Acquisition
Next Article 1c170e35e51892b87d71e3f846735844 Underdog Partners with Crypto.com to Revolutionize Sports Betting with Event Contracts
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
Mixed Trading on Wall Street as Markets Anticipate Federal Reserve’s Interest Rate Decision
K67I3TQBWJEQDK5HOQPPCADXCI
Solana Validators Approve Major Alpenglow Upgrade to Enhance Decentralisation and Reduce Latency
2da47252f94b6178d17c7a84fa44a06322d70883 2400x1597
CleanCore Solutions Buys 200 Million Dogecoin, Aiming for One Billion Tokens
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Stocks
  • DeFi
  • Blockchain
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?