Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Google’s Chicago Headquarters Project Seen as Catalyst for Loop Revival

      June 24, 2026

      AI Data Center Gold Rush Built on Trillions in Hidden Debt

      June 24, 2026

      Runaway Intelligence, Rudderless Oversight

      June 24, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Google’s Chicago Headquarters Project Seen as Catalyst for Loop Revival

        June 24, 2026

        Steering Wheel Faces Uncertain Future as Autonomous Vehicle Technology Advances

        June 24, 2026

        Atlanta Investor Accelerates Capital Deployment Amid Expanding Private Equity Opportunities

        June 24, 2026

        California High-Speed Rail Looks To Data Centers As Funding Lifeline

        June 23, 2026

        Apple Investors Demand Results as AI Patience Runs Thin

        June 23, 2026
      • AI

        AI Data Center Gold Rush Built on Trillions in Hidden Debt

        June 24, 2026

        Jeff Bezos Bets Big on AI-Powered Materials Discovery

        June 24, 2026

        Steering Wheel Faces Uncertain Future as Autonomous Vehicle Technology Advances

        June 24, 2026

        Atlanta Investor Accelerates Capital Deployment Amid Expanding Private Equity Opportunities

        June 24, 2026

        Anthropic Seeks Reversal of U.S. Restrictions on Frontier AI Models

        June 23, 2026
      • Security

        U.S. Commits $500 Million to AI-Driven Push Against China’s Chip Material Dominance

        June 21, 2026

        Hackers Turn Everyday Home Devices Into Cover for Global Cyberattacks

        June 20, 2026

        U.S. Alarm Grows Over Foreign Dependence for Advanced Chip Manufacturing

        June 20, 2026

        Election Betting Boom Draws Congressional Scrutiny Over Democracy and Market Influence

        June 18, 2026

        Trump Administration Moves To Assert Greater Control Over Advanced AI Models

        June 18, 2026
      • Health

        Data Center Noise Complaints Fuel Growing Grassroots Revolt Against AI Infrastructure Expansion

        June 22, 2026

        FDA Advisory Panel Unanimously Backs Moderna’s mRNA Flu Vaccine for Adults 50 and Older

        June 21, 2026

        Utah Becomes Ground Zero in the Battle Over AI Doctors

        June 21, 2026

        Trump Administration Backs Musk’s xAI in High-Stakes Mississippi Emissions Lawsuit

        June 18, 2026

        Most Parents Are Tracking Their Adult Children and the Trend Raises Questions About Independence

        June 17, 2026
      • Science

        FDA Advisory Panel Unanimously Backs Moderna’s mRNA Flu Vaccine for Adults 50 and Older

        June 21, 2026

        3D-Printed Batteries Could Reshape the Future of Energy Storage

        June 20, 2026

        Titan Implosion Report Reveals Preventable Engineering Failures Behind Deadly Disaster

        June 20, 2026

        Space-Based Data Centers Emerge as the Next AI Infrastructure Battleground

        June 19, 2026

        Bronx Physicist Becomes First Recipient Of Advanced 3D-Printed Robotic Arm

        June 14, 2026
      • Tech

        Jeff Bezos Bets Big on AI-Powered Materials Discovery

        June 24, 2026

        Atlanta Investor Accelerates Capital Deployment Amid Expanding Private Equity Opportunities

        June 24, 2026

        Bezos Predicts AI Boom Will Spark Labor Shortage Rather Than Mass Unemployment

        June 23, 2026

        Nvidia Chief Calls for New Social Norms as AI Reshapes Daily Life

        June 23, 2026

        Musk’s SpaceX-Tesla Merger Talk Signals Push Toward a Unified Tech Empire

        June 22, 2026
      TallwireTallwire
      Home»Tech»Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads
      Tech

      Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads

      Updated:December 25, 20253 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads
      Widespread npm Supply-Chain Hack Hits 2+ Billion Weekly Downloads
      Share
      Facebook Twitter LinkedIn Pinterest Email

      Aikido Security Ltd. has revealed what is now regarded as the largest npm supply-chain attack to date, in which threat actors infiltrated 18 widely used npm packages—such as chalk, debug, and ansi-styles—that collectively account for more than 2.6 billion downloads per week, by phishing maintainers to reset two-factor authentication and push malware-laden versions that hijack cryptocurrency transactions in browsers. For example, injected code intercepts functions like fetch, XMLHttpRequest, and wallet APIs (window.ethereum, Solana, etc.), enabling so-called “crypto-clipper” malware to silently redirect funds. Security experts warn developers to roll back to known safe versions, audit recent updates, and be cautious with crypto interactions.

      Sources: BeinCrypto, The Register, SiliconANGLE

      Key Takeaways

      – Supply-chain attackers leveraged phishing to breach npm maintainers’ 2FA, enabling tampering with high-profile packages downloaded billions of times weekly.

      – Malicious code—camouflaged as trusted updates—can hijack crypto transactions in-browser, redirecting funds via wallet API interception.

      – Developers must audit their dependencies closely, revert to verified safe versions, and treat crypto-enabled code with enhanced scrutiny.

      In-Depth

      In a sobering demonstration of how deeply the npm ecosystem is woven into modern software development—and how vulnerable that integration can make us—security researchers with Aikido Security have confirmed a massive supply-chain breach that compromised 18 npm packages downloaded more than 2.6 billion times each week.

      The attackers executed a phishing attack that reset two-factor authentication for targeted maintainers, then published poisoned versions of their packages. Key libraries such as chalk, debug, and ansi-styles were rigged with crypto-stealing malware that operates by intercepting browser-level APIs—like fetch, XMLHttpRequest, and wallet interfaces such as MetaMask and Solana—effectively hijacking cryptocurrency transfers without raising suspicion.

      Known as a “crypto-clipper” attack, this technique replaces legitimate wallet addresses with attacker-controlled ones, often invisibly to users. While the full scope of theft remains undetermined, experts urge developers to rely only on previously verified package versions, thoroughly audit recent changes, and exercise caution when deploying or using crypto-involved code. The incident serves as yet another wake-up call on the fragility of open-source software supply chains, where even trusted tools may be weaponized when security safeguards—like phishing resistance and deployment validation—fail.

      This attack underscores two practical imperatives. First, rigorous supply-chain hygiene is indispensable: Teams should pin dependency versions, monitor integrity signals, and use reproducible builds. Second, for developers handling cryptocurrency or sensitive operations, additional layers of trust—manual code review, wallet confirmation mechanisms, or hardware security modules—should be considered essential, not optional. In today’s environment, reliance on convenience without conservative validation may invite serious consequences.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleWhy Many AI Investments Aren’t Paying Off
      Next Article Windows 11 Patch Sparks Major Streaming Headaches

      Related Posts

      Google’s Chicago Headquarters Project Seen as Catalyst for Loop Revival

      June 24, 2026

      Steering Wheel Faces Uncertain Future as Autonomous Vehicle Technology Advances

      June 24, 2026

      Atlanta Investor Accelerates Capital Deployment Amid Expanding Private Equity Opportunities

      June 24, 2026

      California High-Speed Rail Looks To Data Centers As Funding Lifeline

      June 23, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Google’s Chicago Headquarters Project Seen as Catalyst for Loop Revival

      June 24, 2026

      Steering Wheel Faces Uncertain Future as Autonomous Vehicle Technology Advances

      June 24, 2026

      Atlanta Investor Accelerates Capital Deployment Amid Expanding Private Equity Opportunities

      June 24, 2026

      California High-Speed Rail Looks To Data Centers As Funding Lifeline

      June 23, 2026
      Popular Topics
      UAE Tech Tim Cook Satya Nadella Samsung Tesla Series B Tesla Cybertruck Software starlink spotlight trending SpaceX Space Viral Taiwan Tech Sundar Pichai Stocks Satellite Startup Series A
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.