• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: DeFi Faces Massive Supply Chain Attack as JavaScript Packages Injected with Crypto-Stealing Malware
Share
  • bitcoinBitcoin(BTC)$71,195.00
  • ethereumEthereum(ETH)$2,103.42
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$657.45
  • rippleXRP(XRP)$1.40
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$88.78
  • tronTRON(TRX)$0.291584
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.01
  • dogecoinDogecoin(DOGE)$0.095927
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
DeFi

DeFi Faces Massive Supply Chain Attack as JavaScript Packages Injected with Crypto-Stealing Malware

News Desk
Last updated: September 9, 2025 3:57 pm
News Desk
Published: September 9, 2025
Share
GLKQCBUQ6RCHJBHSIFXSNZBA7Q
Credits: www.dlnews.com

A significant supply chain attack has struck the decentralized finance (DeFi) sector, raising alarms about potential vulnerabilities in crypto wallets. Hackers reportedly poisoned JavaScript packages, infusing them with crypto-stealing malware that, collectively, had been downloaded over 2.6 billion times in a single week. The incident has prompted rapid responses from DeFi protocols and wallet providers who are working to reassure users of their safety.

This alarming development is emblematic of the broader issues facing DeFi, a $204 billion ecosystem that now finds itself exposed to unforeseen points of failure. Cybercriminal behavior in the crypto space has escalated sharply in 2025, with hackers reportedly stealing $2.2 billion from various protocols—a staggering 77% increase from the total stolen throughout 2024, according to DefiLlama.

Despite the scale of the attack, the actual financial loss has been minimal so far. An Ethereum address connected to the hackers has reportedly received only about $500 in stolen crypto, according to Arkham Intelligence. This contrasts sharply with the more impactful thefts seen in previous breaches, such as the $1.4 billion stolen from the Bybit exchange earlier this year by suspected North Korean hackers.

The breach stemmed from a phishing attack on a developer responsible for over a dozen widely-used JavaScript packages crucial to DeFi functionality. While the compromises did not result in any critical system failures, they caused significant concern among users. The hackers exploited the compromised packages, inserting malicious code designed to intercept and redirect crypto transaction flows into their own wallets as users initiated transfers.

Security experts caution that the potential risk is primarily for individuals accessing compromised applications through the web. As a precaution, users are advised to refrain from completing any transactions until DeFi protocols and wallet providers have confirmed the situation is resolved. Although the attack has drawn comparisons to previous high-profile breaches, the community’s response is primarily focused on ensuring that further damage is averted.

The incident serves as a stark reminder of the fragility that can exist even in systems designed for decentralization. While blockchain technology is celebrated for its resilience against central points of failure, such attacks reveal vulnerabilities that lie beyond the control of developers. The ongoing cleanup in the wake of the attack is expected to consume thousands of hours of engineering and security teams’ time globally, illustrating the significant impact that such threats can have.

In other developments related to DeFi governance this week, a vote is underway within the Ethereum Name Service (ENS) community regarding the adoption of the Security Alliance’s Safe Harbor Agreement. Additionally, Gauntlet has proposed renewing its partnership with Compound, while Lisk DAO has voted to deploy liquidity to Aerodrome using Arrakis.

Furthermore, amid rising concerns, discussions have erupted in the crypto community regarding the security implications of coding practices employed by exchanges. A recent revelation that approximately half of Coinbase’s code is written using artificial intelligence has drawn criticism from users, especially in light of a recent security incident where hackers compromised data belonging to nearly 70,000 users.

Hydration Launches HOLLAR, a New Stablecoin Aimed at Maintaining $1 Peg on Polkadot
Major Cryptocurrency Whale Moves $10M from Binance to DeFi, Ignites Ethereum Speculation
Decentralized Exchange Bunni Loses $2.3 Million in Ethereum Exploit
RippleX Unveils Next Phase of XRPL Institutional DeFi Roadmap Focused on Compliance and Lending
21Shares Launches DYDX ETP to Enhance Institutional Access to Decentralized Finance
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article c518322f46ebaad45a52667d2d1bddf65591310a 3538x2358 CoreWeave Launches Venture Capital Arm Focused on AI Startups, Shares Rise 9%
Next Article 108194187 1756986228781 gettyimages 2228223632 US JOBS Labor Market Shows Major Job Losses in Revised Data, Raising Economic Concerns
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
2247a430042a795b2891636568dd56f0
Bitcoin Surpasses Gold in Inflows Amid Iran Conflict
27fc2710 1e66 11f1 bfdf e31e5d2850a0
Stocks Struggle as Inflation Concerns and Oil Prices Rise Amid Ongoing Iran Conflict
108262740 1770405841884 gettyimages 2259642715 FARM IPO
Midday Market Moves: Adobe Drops on CEO Announcement, Ulta Beauty and Fertilizer Stocks Slide
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • Company
  • News
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?