Major NPM Supply-Chain Attack Compromises Packages with Over 2 Billion Weekly Downloads

Major NPM Supply-Chain Attack Compromises Packages with Over 2 Billion Weekly Downloads

A major supply-chain attack targeted the npm ecosystem by hijacking popular JavaScript packages used worldwide. The malicious code was designed to steal cryptocurrency by intercepting transactions involving Bitcoin, Ethereum, and Solana. #NpmAttack #CryptocurrencyTheft

Keypoints

  • An attack compromised at least 20 npm packages with over two billion weekly downloads.
  • The malicious code aimed to steal cryptocurrencies by intercepting transactions.
  • Hackers hijacked network traffic and APIs to redirect cryptocurrency transactions.
  • The affected packages are widely used for styling, debugging, and core web development functions.
  • This incident underscores the risks inherent in modern software dependency chains.

Read More: https://dailydarkweb.net/major-npm-supply-chain-attack-compromises-packages-with-over-2-billion-weekly-downloads/