De-fi
Massive Software Supply-Chain Hack Targeting Crypto Ends with Pennies Stolen – Crypto News
One web developer’s compromised npm account triggered a large-scale supply chain attack, but the hacker only got a few cents in crypto, analysts say.
An unknown hacker pulled off what may be the largest software supply-chain attack ever, but still made less than the price of many memecoins.
On Monday, Sept. 8, a hacker broke into the account of a well-known JavaScript developer known as “qix” and pushed malicious updates to dozens of widely used software tools for building websites and apps, which together are downloaded more than two billion times each week.
After gaining access, the hacker added malicious code to all of the developer’s packages, which wasn’t a virus in the traditional sense but was still designed to steal cryptocurrency from users’ crypto wallets in browsers.
The attack immediately caused chaos as developer updates are usually automatically trusted, so when new versions come in, many projects and apps accept them without checking, letting the hacker’s code spread fast.
Snir Levi, founder and CEO of compliance and threat management platform Nominis, told The Defiant that the modern software supply chain is “incredibly interconnected,” as a single compromised npm account can cascade across thousands of projects and businesses in minutes, because code reuse is the “backbone of the entire ecosystem.” Npm is a registry for JavaScript software packages.
“The stakes aren’t just technical – a malicious package in a critical dependency can impact millions of users, move billions of dollars, and undermine trust in the integrity of the industry. This incident highlights that security isn’t just about protecting infrastructure; it’s about protecting every link in a vast, invisible web of trust,” Levi explained.
The malicious code, mainly targeting Ethereum and Solana transactions, was created to swap destination addresses to the hacker’s wallet, the Security Alliance wrote in a post-attack blog post on Monday.
The cybersecurity experts say that the code also tried to rewrite crypto addresses inside web traffic with look-alike ones.
‘Generational Fumble’
While on paper the attack was catastrophic, in terms of actual losses, the Security Alliance says that the hacker made only about $0.05 worth of ETH and $20 in a memecoin.
“Despite the magnitude of the breach, the attacker appears to have only ‘stolen’ around 5 cents of ETH and 20 USD of a memecoin with a whopping 588 USD of trading volume over the past 24 hours,” the Security Alliance said.
Commenting on the attack in an X post, samczsun, a pseudonymous white hat hacker and the founder of the Security Alliance, described the incident as a “generational fumble, the likes of which we will probably never see again.”
Harry Donnelly, CEO of digital asset recovery company Circuit, suggested in commentary for The Defiant that this attack is far from the last one as there are “many dependencies and vulnerabilities in the crypto supply chain.”
“This attack is an example of how something as small as an open-source package installed by one developer can create an unintended attack vector. Having measures in place to respond to malicious activity, even if the payload is replaced, is critically important to prevent funds from being stolen,” Donnelly added.
-
others7 days ago
Japan Foreign Investment in Japan Stocks up to ¥528.3B in December 12 from previous ¥96.8B – Crypto News
-
Technology7 days agoOnePlus 15R vs Pixel 9a: Which phone is the best buy under ₹50,000? Display, camera, processor and more compared – Crypto News
-
Blockchain5 days agoThis Week in Stablecoins: Winning the Back Office – Crypto News
-
Blockchain1 week agoJPMorgan Prepares to Launch First Tokenized Money Market Fund – Crypto News
-
Technology4 days agoApple iPhone 16 price drops to ₹40,990 in Croma’s Cromtastic December Sale: How the deal works – Crypto News
-
others6 days agoAustralian Dollar loses as US Dollar advances before Michigan Sentiment Index – Crypto News
-
Business4 days ago
XRP Holders Eye ‘Institutional Grade Yield’ as Ripple Engineer Details Upcoming XRPL Lending Protocol – Crypto News
-
Technology4 days agoApple iPhone 16 price drops to ₹40,990 in Croma’s Cromtastic December Sale: How the deal works – Crypto News
-
Cryptocurrency1 week agoBlockworks launches investor relations platform with Solana – Crypto News
-
Blockchain7 days agoBlockchain’s Institutional Future Is Private and Permissioned – Crypto News
-
Business5 days ago
DOGEBALL Presale: A Boost to Bring P2E Games Back into the Spotlight – Crypto News
-
Business5 days ago
125 Crypto Firms Mount Unified Defense as Banks Push to Block Stablecoin Rewards – Crypto News
-
others4 days ago
XRP Holders Eye ‘Institutional Grade Yield’ as Ripple Engineer Details Upcoming XRPL Lending Protocol – Crypto News
-
Technology4 days agoApple iPhone 16 price drops to ₹40,990 in Croma’s Cromtastic December Sale: How the deal works – Crypto News
-
Blockchain4 days agoLitecoin Follows Bitcoin’s Momentum, But Resistance Looms At $79.60 – Crypto News
-
Business1 week ago
Bitcoin Faces Slide Towards $70K as Japan Rate Hike Odds Spike – Crypto News
-
Technology1 week agoSamsung tipped to raise Galaxy A series price in India starting Monday: here’s what to expect – Crypto News
-
Cryptocurrency1 week agoTranshumanism Branded a ‘Death Cult’ as Thinkers Clash Over Humanity’s Future – Crypto News
-
Cryptocurrency1 week agoCapital gets selective – Blockworks – Crypto News
-
others1 week ago
Low-Fee vs. High-Leverage – How to Choose the Optimal Exchange for Your Trading Strategy? – Crypto News
-
Technology1 week agoUS Puts Tech Deal With UK on Hold – Crypto News
-
Blockchain1 week agoCiti Says Identity Is the New Gatekeeper for Financial Blockchains – Crypto News
-
Blockchain7 days agoBitcoin on Track For 4th Annual Decline Despite Crypto Adoption – Crypto News
-
Technology4 days ago
Michael Saylor Sparks Debate Over Bitcoin’s Quantum Risk as Bitcoiners Dismiss It as ‘FUD’ – Crypto News
-
Blockchain4 days agoCrypto Market Sentiment Not Fearful Enough For Bottom: Santiment – Crypto News
-
Technology4 days agoApple iPhone 15 price drops to ₹36,490 in Croma Cromtastic December Sale: How the deal works – Crypto News
-
Cryptocurrency1 week agoDollar dominance can’t be manufactured – Crypto News
-
Blockchain1 week agoXRP Holders Labeled ‘Uneducated Perma Bulls’ By Veteran Trader – Crypto News
-
Business1 week ago
Bitcoin Faces Slide Towards $70K as Japan Rate Hike Odds Spike – Crypto News
-
others1 week agoInsider Drains $345,014 From Accounts Within Weeks of Joining US Lender – Here’s How – Crypto News
-
Cryptocurrency1 week agoAI Agents and On-Chain Finance Are About to Reshape Everything – Crypto News
-
others1 week ago
Metaplanet CEO Teases “Crucial” Bitcoin Buy Decision at Upcoming EGM, Stock Wavers – Crypto News
-
Cryptocurrency1 week agoXRP Price Analysis for December 14 – Crypto News
-
Cryptocurrency1 week agoBitcoin and Ethereum Wobble as US Reports Highest Unemployment Rate Since 2021 – Crypto News
-
others1 week agoJapanese Yen strengthens as BoJ rate hike speculation grows – Crypto News
-
Metaverse1 week ago
How companies are using AI to squeeze more from your wallet – Crypto News
-
Cryptocurrency6 days agoWhy quantum computing is becoming a real concern for Bitcoin – Crypto News
-
Blockchain5 days agoCoinbase Launches Service to Help Businesses Create Tokens – Crypto News
-
Business5 days ago
Bitcoin Price Alarming Pattern Points to a Dip to $80k as $2.7b Options Expires Today – Crypto News
-
Metaverse5 days agoAI Tool of the Week: Transform marketing concepts instantly. – Crypto News
-
Business4 days ago
Ethereum Faces Selling Pressure as BitMEX Co-Founder Rotates $2M Into DeFi Tokens – Crypto News
-
others4 days agoElliott Wave, seasonality, and cycles indicate more upside – Crypto News
-
others4 days agoElliott Wave, seasonality, and cycles indicate more upside – Crypto News
-
Cryptocurrency4 days agoIs ETH Ready for Sustained Recovery or Another Rejection Looms? – Crypto News
-
Blockchain4 days agoCrypto Market Sentiment Not Fearful Enough For Bottom: Santiment – Crypto News
-
Blockchain4 days agoLitecoin Follows Bitcoin’s Momentum, But Resistance Looms At $79.60 – Crypto News
-
others1 week ago
Bitcoin Faces Slide Towards $70K as Japan Rate Hike Odds Spike – Crypto News
-
others1 week ago
Bitcoin Faces Slide Towards $70K as Japan Rate Hike Odds Spike – Crypto News
-
Technology1 week agoSamsung tipped to raise Galaxy A series price in India starting Monday: here’s what to expect – Crypto News
-
others1 week agoWhale.io Launches WHALE NFT Collection on Solana: New Pre-Market Phase Ahead of TGE – Crypto News
