logo

Crypto wallets targeted in widespread hack of npm, GitHub

ID: 4ab568f4-cc2d-5fec-ae06-3cbe319c4192

STIX ID: report--4ab568f4-cc2d-5fec-ae06-3cbe319c4192

Feed Name: ReversingLabs Blog

Threat Score
80/100

Date Published: 2025-09-09

Date Updated: 2026-04-29

Author: Paul Roberts

...
...

Security researchers report a widespread phishing-driven supply-chain campaign that compromised numerous npm and GitHub maintainer accounts (including the ~qix account), injecting heavily obfuscated JavaScript into popular packages that monitors wallet interactions and replaces recipient addresses with attacker-controlled "drainer" wallets; multiple packages with billions of downloads were affected and researchers have identified related malicious files, hashes, phishing domains, and wallet addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.