Crypto Boost News

Crypto Boost News

Malicious NPM Packages Raise New Security Risks for Crypto Wallets

Published: September 9th. 2025, Updated: July 18th. 2026

News & Events

Researchers Identify Malicious Code in Key JavaScript Packages

A suspected software supply chain attack is currently impacting the cryptocurrency ecosystem through several compromised JavaScript packages, according to a group of security researchers operating under the name JDSTAERK. The incident, which targets packages from the popular Node Package Manager (NPM) registry, may indirectly put users' crypto wallets at risk.

Developer Account Compromised

The researchers have indicated that a developer known as "qix" had their NPM account breached, enabling attackers to update multiple packages with malicious code. These impacted packages are dependencies widely used in both server environments and web applications around the world.

This supply chain compromise allows threat actors to distribute malware designed to quietly steal cryptocurrency funds. According to the analysis, the malicious code activates specifically when it detects the presence of a crypto wallet within the application's environment.

How the Malware Operates

  • Passive Mode: If no wallet is present, the malware attempts to exfiltrate data to an external server.
  • Active Threat: When a crypto wallet is detected, the malware intercepts communication between the wallet and the user.

In cases where a wallet is found, the attackers exploit transaction workflows. When a user initiates a transaction, the malware intercepts the details before they are relayed to the wallet for signing. It then overwrites the legitimate destination address in memory with an address controlled by the attacker. If the user does not verify the address during transaction confirmation, funds are inadvertently sent to the attacker's wallet.

Wider Risk to Crypto Ecosystem

While developers are the primary targets, the widespread use of affected NPM packages broadens the potential impact. This indirect exposure puts end users�including those relying on popular wallets�at risk without their direct involvement.

Charles Guillemet, CTO of Ledger, has publicly acknowledged the attack, underlining the ongoing need for vigilance against software supply chain threats.

The incident highlights the importance of strict code review processes and wallet-level transaction verification to mitigate the effects of supply chain attacks in the crypto sector.

Related content

Want to get 100 USD with Binance?
Loading...
x