NPM Attack: Javascript Library Compromise Goes After Bitcoin Wallets
Bitcoin Magazine NPM Attack: Javascript Library Compromise Goes After Bitcoin Wallets A major NPM developer, qix, has had their account compromised. It was used to push malware that targets and searches for bitcoin and c...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Bitcoin Magazine
NPM Attack: Javascript Library Compromise Goes After Bitcoin Wallets
A major NPM developer, qix, has had their account compromised. It was used to push malware that targets and searches for bitcoin and cryptocurrency wallets on users devices. If detected, the malware would patch the code functions used to coordinate transaction signing, and replace the address a user is trying to send money to with one of the malware creator’s own addresses.
This should mostly be a concern for web wallet users, so in the Bitcoin ecosystem Ordinals or Runes/other token users, as unless an update for your normal software wallet happened to be pushed just earlier today with the compromised dependency, or if your wallet dynamically loads code directly from the wallet back end bypassing the app-store, you should be fine.
NPM is a package manager for Node.js, a popular Javascript framework. This means it is used to grab large sets of pre-written code used for common functionality to be integrated into different programs without the developer having to rewrite basic functions themselves.
The targeted packages were not cryptocurrency specific, but packages used by countless numbers of normal applications built with Node.js, not just cryptocurrency wallets.
If you are using a hardware wallet in combination with your web wallet, take extra care to verify on the device itself that the destination address you are sending too is correct before signing anything.
If you are using software keys in the web wallet itself, it would be advisable to not open them or transact until you are certain you are not running a vulnerable version of the wallet. The safest course of action would be waiting for an announcement from the team developing the wallet you use.
This post NPM Attack: Javascript Library Compromise Goes After Bitcoin Wallets first appeared on Bitcoin Magazine and is written by Shinobi.
Why this matters
This bitcoin story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Bitcoin MagazineRelated market context
Nearly $20 million in XRP drained from 6,678 wallets across six attack waves
Nearly $20 million of XRP was drained from thousands of hardware wallets in six waves spanning nearly a week. Blockchain analysis...
iPhone Crypto App Hides Malicious Code as Attacker Wallet Nets $580K
An iPhone app promoted as a read-only crypto monitoring tool carried code capable of accessing other apps and sensitive wallet dat...
Cosmos Hub Restarts and Moves $2.1 Million in Stolen Tokens Out of an Attacker’s Wallet
The Cosmos Hub resumed producing blocks Wednesday morning after its validators halted the network for nearly 25 hours. In the firs...
Mid-Sized Bitcoin Wallets Add 113,950 Bitcoin as Price Rally Nears Test
Wallets holding between 100 and 1,000 BTC have added 113,950 Bitcoin since July 15, lifting their combined holdings 2.22% to 5.24...
Elliptic launches Pulse, an AI tool that lets any cop screen crypto wallets in seconds
Pulse democratizes crypto investigations, enabling faster, more efficient law enforcement responses and potentially reducing crypt...
Bitcoin’s 100-1,000 BTC wallets accumulate 113,950 BTC since July 15
Institutional interest in Bitcoin is rising, potentially stabilizing the market and influencing future price dynamics and adoption...