Massive NPM Malware Attack Yields Only $50 in Theft

Massive NPM Malware Attack Yields Only $50 in Theft

Kane Pepi

Last Updated July 29, 2025

Cryptocurrencies are considered a high-risk asset class. Investing in them may result in the loss of part or all of your capital. The content on this website is intended solely for informational and educational use and should not be interpreted as financial or investment advice.

Best ICO was developed by blockchain experts to help traders and investors identify the best new ICOs and most promising crypto presales in the market. As one of the top ICO listing websites, we maintain rigorous standards to deliver accurate, timely information about the latest cryptocurrency ICOs and best upcoming crypto ICO opportunities.

Our team specializes in uncovering the ICO projects 2025 will offer, providing in-depth analysis of tokenomics, team credentials, and growth potential. We focus particularly on the best ICO crypto candidates, evaluating each project’s viability as a crypto to invest in.

A major breach involving the Node Package Manager (NPM) platform has affected several widely used JavaScript libraries. Hackers accessed the account of a known developer and inserted malware into trusted packages. These packages have been downloaded more than a billion times.

The attack was designed to target cryptocurrency wallets, but according to security group Security Alliance, the total amount stolen so far is under $50. The malware was active for a short time before being identified and removed.

Malware Spread Through Common Packages

The attack used a method known as a crypto-clipper. This type of malware changes wallet addresses during transactions. If a user copies a wallet address, the clipper replaces it with one owned by the attacker.

Security Alliance linked the attack to one Ethereum address, “0xFc4a48.” This wallet received several small transactions, including tokens such as BRETT, ANDY, DORK, VISTA, and GONDOLA. At first, only five cents in Ether were stolen. A few hours later, the total had grown to around $50.

One researcher from the group posted, 

“You could have unfettered access to millions of developer workstations… You profit less than 50 USD.” 

The scale of the access compared to the low value taken has surprised many in the cybersecurity space.

Risk to Developers Remains Despite Low Theft

The malware was hidden in packages like chalk, strip-ansi, and color-convert. These are small tools that are widely used, often as part of other software. Even developers who didn’t directly install these packages may have been exposed if they updated or built software recently.

The attacker uploaded the malware through a developer account with high trust in the community. That made the infected versions appear safe and caused them to spread quickly. Developers have been advised to stop using any affected versions and check for recent updates.

0xngmi, the founder of DefiLlama, said, only crypto projects that updated after the bad code was pushed are likely at risk. And even then, users still have to approve the transaction.

Major Wallet Apps Say They Are Not Affected

Several well-known crypto wallets, including Ledger, MetaMask, and Phantom, confirmed that they are not using the infected packages. Ledger said its system has “multiple layers of defense.” MetaMask also reported that its apps remain unaffected.

Uniswap, Revoke.cash, Blast, and Aerodrome gave similar updates. Each confirmed that they do not rely on the compromised packages or had not updated to the infected versions.

Meanwhile, the issue has raised concern across the developer community, especially in crypto. While the damage was low in terms of stolen funds, many teams are now reviewing their security and package dependencies more closely.

More Articles

 Ethereum Faces Record ETF Outflows While Whales Accumulate $1.7B

Key Takeaways: Ethereum faces a critical juncture as institutional investors pull unprecedented amounts from exchange-traded funds while sophisticated traders accumulate..

Crypto Daily News – September 27, 2025

Vitalik Buterin criticizes EU chat law over privacy fears; Kraken raises $500M amid IPO talk; UK crypto firms push for..

By Kane Pepi

Kane Pepi is an established financial and cryptocurrency writer with over 2,000 articles, tutorials, and market insights under his belt. Kane has a reputation for offering concise explanations of complex financial matters due to his competence in specialized fields such as asset valuation and analysis, portfolio management, and financial crime prevention. He has a Bachelor’s Degree in Finance, a Master’s Degree in Financial Crime, and is now working on his Doctorate degree, which will focus on the difficulties of money laundering in the cryptocurrency and blockchain technology industries. Kane’s abundance of knowledge and expertise in the sector make him an invaluable resource for anybody navigating the world of finance and cryptocurrency.

More Articles

You might also like