Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

    What's Hot

    AI Productivity Gains Concentrated Among High-Skilled Workers, Study Finds

    February 28, 2026

    Single Compromised Account Exposes 1.2 Million French Banking Records

    February 28, 2026

    Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

    February 28, 2026
    Facebook X (Twitter) Instagram
    • Tech
    • AI
    • Get In Touch
    Facebook X (Twitter) LinkedIn
    TallwireTallwire
    • Tech

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026

      Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

      February 27, 2026

      OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

      February 27, 2026

      Large Hadron Collider Enters Third Shutdown For Major Upgrade

      February 26, 2026

      Stellantis Faces Massive Losses and Strategic Shift After Misjudging EV Market Demand

      February 26, 2026
    • AI

      AI Productivity Gains Concentrated Among High-Skilled Workers, Study Finds

      February 28, 2026

      X to Let Users Mark Posts ‘Made With AI’ as Platform Eyes Voluntary Disclosure Feature

      February 27, 2026

      Uber Rolls Out “Uber Autonomous Solutions” To Support Third-Party Robotaxi Partners

      February 27, 2026

      Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

      February 27, 2026

      OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

      February 27, 2026
    • Security

      Single Compromised Account Exposes 1.2 Million French Banking Records

      February 28, 2026

      PayPal Data Breach Exposed Customer Personal Information For Months

      February 27, 2026

      Discord Ends Persona Age Verification Trial Amid Privacy Backlash

      February 27, 2026

      FBI Issues Alert on Outdated Wi-Fi Routers Vulnerable to Cyber Attacks

      February 25, 2026

      Wikipedia Blacklists Archive.Today After DDoS Abuse And Content Manipulation

      February 24, 2026
    • Health

      Social Media Addiction Trial Draws Grieving Parents Seeking Accountability From Tech Platforms

      February 19, 2026

      Portugal’s Parliament OKs Law to Restrict Children’s Social Media Access With Parental Consent

      February 18, 2026

      Parents Paint 108 Names, Demand Snapchat Reform After Deadly Fentanyl Claims

      February 18, 2026

      UK Kids Turning to AI Chatbots and Acting on Advice at Alarming Rates

      February 16, 2026

      Landmark California Trial Sees YouTube Defend Itself, Rejects ‘Social Media’ and Addiction Claims

      February 16, 2026
    • Science

      Microsoft Claims 100 Percent Renewable Energy Match Across Global Electricity Use

      February 28, 2026

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026

      Large Hadron Collider Enters Third Shutdown For Major Upgrade

      February 26, 2026

      Google Phases Out Android’s Built-In Weather App, Replacing It With Search-Based Forecasts

      February 25, 2026

      Microsoft’s Breakthrough Suggests Data Could Be Preserved for 10,000 Years on Glass

      February 24, 2026
    • Tech

      Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

      February 28, 2026

      Zuckerberg Testifies In Landmark Trial Over Alleged Teen Social Media Harms

      February 23, 2026

      Gay Tech Networks Under Spotlight In Silicon Valley Culture Debate

      February 23, 2026

      Google Co-Founder’s Epstein Contacts Reignite Scrutiny of Elite Tech Circles

      February 7, 2026

      Bill Gates Denies “Absolutely Absurd” Claims in Newly Released Epstein Files

      February 6, 2026
    TallwireTallwire
    Home»Tech»Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads
    Tech

    Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads

    Updated:December 25, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads
    Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Aikido Security Ltd. has revealed what is now regarded as the largest npm supply-chain attack to date, in which threat actors infiltrated 18 widely used npm packages—such as chalk, debug, and ansi-styles—that collectively account for more than 2.6 billion downloads per week, by phishing maintainers to reset two-factor authentication and push malware-laden versions that hijack cryptocurrency transactions in browsers. For example, injected code intercepts functions like fetch, XMLHttpRequest, and wallet APIs (window.ethereum, Solana, etc.), enabling so-called “crypto-clipper” malware to silently redirect funds. Security experts warn developers to roll back to known safe versions, audit recent updates, and be cautious with crypto interactions.

    Sources: BeinCrypto, The Register, SiliconANGLE

    Key Takeaways

    – Supply-chain attackers leveraged phishing to breach npm maintainers’ 2FA, enabling tampering with high-profile packages downloaded billions of times weekly.

    – Malicious code—camouflaged as trusted updates—can hijack crypto transactions in-browser, redirecting funds via wallet API interception.

    – Developers must audit their dependencies closely, revert to verified safe versions, and treat crypto-enabled code with enhanced scrutiny.

    In-Depth

    In a sobering demonstration of how deeply the npm ecosystem is woven into modern software development—and how vulnerable that integration can make us—security researchers with Aikido Security have confirmed a massive supply-chain breach that compromised 18 npm packages downloaded more than 2.6 billion times each week.

    The attackers executed a phishing attack that reset two-factor authentication for targeted maintainers, then published poisoned versions of their packages. Key libraries such as chalk, debug, and ansi-styles were rigged with crypto-stealing malware that operates by intercepting browser-level APIs—like fetch, XMLHttpRequest, and wallet interfaces such as MetaMask and Solana—effectively hijacking cryptocurrency transfers without raising suspicion.

    Known as a “crypto-clipper” attack, this technique replaces legitimate wallet addresses with attacker-controlled ones, often invisibly to users. While the full scope of theft remains undetermined, experts urge developers to rely only on previously verified package versions, thoroughly audit recent changes, and exercise caution when deploying or using crypto-involved code. The incident serves as yet another wake-up call on the fragility of open-source software supply chains, where even trusted tools may be weaponized when security safeguards—like phishing resistance and deployment validation—fail.

    This attack underscores two practical imperatives. First, rigorous supply-chain hygiene is indispensable: Teams should pin dependency versions, monitor integrity signals, and use reproducible builds. Second, for developers handling cryptocurrency or sensitive operations, additional layers of trust—manual code review, wallet confirmation mechanisms, or hardware security modules—should be considered essential, not optional. In today’s environment, reliance on convenience without conservative validation may invite serious consequences.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhy Many AI Investments Aren’t Paying Off
    Next Article Windows 11 Patch Sparks Major Streaming Headaches

    Related Posts

    Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

    February 27, 2026

    Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

    February 27, 2026

    OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

    February 27, 2026

    Large Hadron Collider Enters Third Shutdown For Major Upgrade

    February 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

    February 27, 2026

    Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

    February 27, 2026

    OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

    February 27, 2026

    Large Hadron Collider Enters Third Shutdown For Major Upgrade

    February 26, 2026
    Popular Topics
    Series A SpaceX UAE Tech Quantum computing Series B Robotics trending Tesla Tesla Cybertruck Sundar Pichai Sam Altman Tim Cook Satya Nadella Ransomware spotlight Qualcomm Taiwan Tech Samsung picks Startup
    Major Tech Companies
    • Apple News
    • Google News
    • Meta News
    • Microsoft News
    • Amazon News
    • Samsung News
    • Nvidia News
    • OpenAI News
    • Tesla News
    • AMD News
    • Anthropic News
    • Elbit News
    AI & Emerging Tech
    • AI Regulation News
    • AI Safety News
    • Quantum Computing News
    • Robotics News
    Key People
    • Sam Altman News
    • Jensen Huang News
    • Elon Musk News
    • Mark Zuckerberg News
    • Sundar Pichai News
    • Tim Cook News
    • Satya Nadella News
    • Mustafa Suleyman News
    Global Tech & Policy
    • Israel Tech News
    • India Tech News
    • Taiwan Tech News
    • UAE Tech News
    Startups & Emerging Tech
    • Series A News
    • Series B News
    • Startup News
    Tallwire
    Facebook X (Twitter) LinkedIn Threads Instagram RSS
    • Tech
    • Entertainment
    • Business
    • Government
    • Academia
    • Transportation
    • Legal
    • Press Kit
    © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

    Type above and press Enter to search. Press Esc to cancel.