npm debug and chalk packages compromised
ID: 4b802f3c-bcb4-5a71-90c0-2743380bd5d2
STIX ID: report--4b802f3c-bcb4-5a71-90c0-2743380bd5d2
Feed Name: Aikido Security's Blog
Aikido detected a supply-chain compromise where 18 popular npm packages were updated with obfuscated JavaScript that injects into browsers, hooks fetch/XMLHttpRequest and wallet APIs (Ethereum, Solana, Tron, Bitcoin, Litecoin, BCH), and silently replaces legitimate crypto payment destinations and transaction fields with attacker-controlled addresses; the attack appears linked to a phishing email to a maintainer and affects packages with billions of weekly downloads, with remediation guidance and IOC lists provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
