logo

npm debug and chalk packages compromised

ID: 4b802f3c-bcb4-5a71-90c0-2743380bd5d2

STIX ID: report--4b802f3c-bcb4-5a71-90c0-2743380bd5d2

Feed Name: Aikido Security's Blog

Threat Score
85/100

Date Published: 2025-09-08

Date Updated: 2026-07-24

...
...

Aikido detected a supply-chain compromise where 18 popular npm packages were updated with obfuscated JavaScript that injects into browsers, hooks fetch/XMLHttpRequest and wallet APIs (Ethereum, Solana, Tron, Bitcoin, Litecoin, BCH), and silently replaces legitimate crypto payment destinations and transaction fields with attacker-controlled addresses; the attack appears linked to a phishing email to a maintainer and affects packages with billions of weekly downloads, with remediation guidance and IOC lists provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.