Dev snared in crypto phishing net, 18 npm packages compromised

Crims have added backdoors to at least 18 npm packages after developer Josh Junon inadvertently authorized a reset of the two-factor authentication protecting his npm account.

The malware targets cryptocurrency transactions on various blockchains such as Ethereum, Bitcoin, Solana, and Tron.

In posts to Bluesky and GitHub on Monday, Junon acknowledged that a phishing email had duped him, allowing miscreants to take over his account.

"Sorry everyone, I should have paid more attention," Junon wrote. "Not like me; have had a stressful week. Will work to get this cleaned up."

The phishing email came from [email protected] rather than npmjs.com, and several other developers have reported receiving a similar message.

Junon (Qix-) on GitHub has contributed to at least 80 npm packages. He identified 18 packages that have been affected. "This appears targeted, or at least with a filter for high downloads," he wrote. "Many other packages on my account are untouched."

Charlie Eriksen, security researcher at Aikido Security, said in a blog post that the firm detected the attack on September 8 at 1316 UTC.

"The packages were updated to contain a piece of code that would be executed on the client of a website, which silently intercepts crypto and web3 activity in the browser, manipulates wallet interactions, and rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user," Eriksen wrote.

The 18 compromised packages include:

Together, these packages account for about two billion downloads per week, said Aikido developer and security advocate Mackenzie Jackson in a LinkedIn post, and represent the largest software supply chain attack to date at npm.

Given that substantial install base, it's likely some applications incorporating those packages were updated to the compromised versions during the approximately two hour period before npm security and other project maintainers started taking the compromised code down. However, it appears the attacker hasn't yet received any funds from the gambit.

Not all the affected packages appear to have been removed, however. At the time this story was filed, [email protected] was still available.

Open source developer Sindre Sorhus suggests the following command line incantation, which requires the ripgrep search tool, to check whether any compromised packages have been installed:

According to ReversingLabs' 2025 Software Supply Chain Security Report, 14 of the 23 crypto-related malicious campaigns in 2024 (61 percent) involved npm, with the remainder linked to the Python Package Index (PyPI). ®

Search
About Us
Website HardCracked provides softwares, patches, cracks and keygens. If you have software or keygens to share, feel free to submit it to us here. Also you may contact us if you have software that needs to be removed from our website. Thanks for use our service!
IT News
May 6
AWS lets agents drive its virtual cloudy desktops - which could cost 500,00 tokens per click

Vendor benchmark finds APIs let you do the job faster and cheaper

May 6
India orders infosec red alert in case Mythos sparks crime spree

Securities regulator urges market players to develop new strategies and nail cyber-basics before AI models fuel mass attacks

May 6
OpenAI exec says company hopes to burn $50B of somebody else's money on compute this year

If the numbers are large enough, perhaps we won't question the math

May 5
Astera speaks softly and carries a big switch

High-speed connectivity without NVLink baggage

May 5
IBM asks DBAs to trust AI to act on their behalf

With help from Google and Intel, Big Blue brings new automation to Db2

May 5
ServiceNow clears agents for landing with new AI control tower

ServiceNow acquisitions Veza and Traceloop join to monitor agents and AI workflows