logo

18 Popular Code Packages Hacked, Rigged to Steal Crypto

ID: 9a2525e7-c420-50a6-a04f-cdb87e6e03a8

STIX ID: report--9a2525e7-c420-50a6-a04f-cdb87e6e03a8

Feed Name: Krebs on Security

Threat Score
78/100

Date Published: 2025-09-08

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

A phishing campaign compromised an NPM maintainer and briefly injected malicious code into at least 18 widely used JavaScript packages (collectively downloaded at massive scale) that intercepted browser wallet activity and rewrote payment destinations to attacker-controlled accounts; the modifications were quickly detected and removed, but the incident underscores severe supply-chain risk, the danger of phishable 2FA, and the need for stronger provenance and attestation for widely used packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.