• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Hacker Infects Popular JavaScript Packages with Crypto-Looting Malware
Share
  • bitcoinBitcoin(BTC)$81,921.00
  • ethereumEthereum(ETH)$2,410.15
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$1.44
  • binancecoinBNB(BNB)$646.47
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$89.14
  • tronTRON(TRX)$0.343016
  • dogecoinDogecoin(DOGE)$0.116145
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

Hacker Infects Popular JavaScript Packages with Crypto-Looting Malware

News Desk
Last updated: September 9, 2025 6:22 pm
News Desk
Published: September 9, 2025
Share
03J6t5phIVDNHysf6Ri2EOl 1.fit lim.size 1200x630.v1757362104
Credits: www.pcmag.com

A significant cybersecurity incident has come to light, revealing that a hacker has compromised over a dozen widely used software packages by infiltrating the account of their maintainer through a phishing attack. This breach involved a set of popular Node Package Manager (npm) packages that are integral for various JavaScript projects, providing functions for tasks like font conversion and color additions.

The compromised packages, which belong to developer Josh Junon, have been downloaded approximately 2 billion times weekly. Junon himself acknowledged the breach, stating, “Yep, I’ve been pwned,” and noted that the attack stemmed from a phishing email that deceitfully appeared to come from npmjs.com—the legitimate domain owned by GitHub. The fraudulent email utilized official logos and was reportedly sent from a fake domain, npmjs[.]help.

The phishing attempt was particularly sophisticated, masquerading as a security notification that urged Junon to update his two-factor authentication settings. A link in the email directed him to a malicious domain that effectively compromised his account, allowing the hacker to modify the npm packages.

Aikido Security characterized this breach as “the largest supply chain compromise in npm history.” The incident is notable, yet the programming community reacted swiftly, bringing attention to the malicious processes embedded within the affected packages. Some of these packages have since been removed from circulation. According to Semgrep, while the malicious versions existed only briefly and did not accumulate downloads, the overall impact of the malware is expected to be minimal.

BleepingComputer reported that three specific criteria needed to be met for a software project to be impacted. The compromised packages showed some potential for harm, though security researcher Florian Roth remarked on the amateurish nature of the payload, suggesting that the attackers had access but lacked sophistication.

Evidence indicates that the hacker may have also targeted other npm package maintainers. The malware they deployed aims to steal cryptocurrency by altering browser transactions. Specifically, it reroutes crypto transactions to the hacker’s designated address, effectively siphoning funds from unsuspecting users. Another security provider, Socket, elaborated on the payload’s functionality, underscoring the risk to those who utilize these npm packages.

As the incident unfolds, the cybersecurity community remains vigilant, emphasizing the need for enhanced security measures to protect against such sophisticated phishing attempts.

Cantor Fitzgerald Launches Gold Protected Bitcoin Fund to Mitigate Risk
Solana DeFi Surges as Whales Drive Record Capital Inflows
Social Security Faces Cash Flow Struggles as It Approaches 90th Anniversary
Three AI Stocks to Invest in Right Now
PIMCO’s Stracke Warns of ‘Cracks’ in Corporate Direct Lending Amid Optimism for Asset-Based Finance
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article apple.webp Rumor Claims Apple to Purchase $1.5 Billion in XRP, Experts Dismiss It as Unfounded
Next Article 68c064dff9db348adc0b21f8 Investors Face Turning Point as “Bad News is Bad News” Looms on the Horizon
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
06Biz Oil Stocks Gas promo clgw facebookJumbo
Oil Prices Tumble as Stock Markets Rise Following Trump’s Decision to Pause U.S. Naval Operation in Strait of Hormuz
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8686362Fjerome powell chair powell answers
S&P 500 at Risk as Kevin Warsh Aims to Shrink Federal Reserve’s Balance Sheet
open graph
MoonPay Acquires DFlow to Enhance Trading Infrastructure and High-Frequency Trading Capabilities
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?