logo

Dev snared in crypto phishing net, 18 npm packages compromised

ID: 6fe45f49-c726-59a4-aa81-889a5cc5211c

STIX ID: report--6fe45f49-c726-59a4-aa81-889a5cc5211c

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-09-08

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Attackers phished an npm package maintainer, reset his 2FA, and published malicious updates to 18 widely used npm packages that injected code into clients to intercept and rewrite cryptocurrency and Web3 transactions (Ethereum, Bitcoin, Solana, Tron). The compromised packages (accounting for ~2 billion downloads/week) were live for about two hours before removal; a ripgrep search pattern (_0x112fa8) and package list were provided as indicators, and no confirmed theft was reported at the time of the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.