{"id":6461,"date":"2025-09-08T21:58:07","date_gmt":"2025-09-08T21:58:07","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=6461"},"modified":"2025-09-08T21:58:07","modified_gmt":"2025-09-08T21:58:07","slug":"npm-packages-with-2-billion-weekly-downloads-hacked-in-main-assault","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=6461","title":{"rendered":"npm Packages With 2 Billion Weekly Downloads Hacked in Main Assault"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"is-style-cnvs-paragraph-callout\">Aikido Safety flagged the most important npm assault ever recorded, with 18 packages like chalk, debug, and ansi-styles hacked to hijack crypto wallets by way of injected code.<\/p>\n<p>Aikido Safety has flagged what could possibly be the most important npm provide chain compromise ever recorded. The account of a long-trusted maintainer generally known as <code>qix<\/code> was hijacked by means of a phishing e mail, and 18 well-liked packages have been altered with malicious code. These packages embrace chalk, debug, and ansi-styles, which collectively signify greater than two billion weekly downloads.<\/p>\n<p>The excellent news is that the timing of the detection was quick sufficient to restrict injury. Aikido\u2019s lead malware researcher, Charlie Eriksen, mentioned the assault was recognized inside 5 minutes and disclosed inside an hour.<\/p>\n<p>What makes this incident particularly severe is the aim of the injected malware. As a substitute of focusing on improvement environments or servers, the code is designed to intervene with cryptocurrency transactions within the browser. <\/p>\n<p>In accordance with researchers, it hooks into <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/metamask-warns-apple-users-disable-icloud-backup\/\" target=\"_blank\" data-type=\"post\" data-id=\"96344\" rel=\"noreferrer noopener\">MetaMask<\/a>, Phantom, and different pockets APIs, altering transaction information earlier than customers signal. The interface reveals the proper recipient, however the funds are redirected to addresses managed by the attacker.<\/p>\n<p>The malware additionally intercepts community visitors and utility calls, recognises codecs throughout Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Money, after which rewrites them with convincing lookalike addresses. Because it operates at each the browser and API stage, it may well make fraudulent transfers seem official.<\/p>\n<p>The complete listing of compromised packages is lengthy, however a few of the most generally used embrace chalk (300 million weekly downloads), debug (358 million), and ansi-styles (371 million). Different affected initiatives vary from low-level utilities like is-arrayish to formatting libraries resembling strip-ansi. <\/p>\n<p>For a lot of builders, these packages are a part of the inspiration of on a regular basis JavaScript functions, that means the malicious variations might already be operating in manufacturing techniques worldwide.<\/p>\n<p>The maintainer <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/bsky.app\/profile\/bad-at-computer.bsky.social\/post\/3lydioq5swk2y\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmed<\/a> on Bluesky that his account was taken over after receiving a phishing e mail from \u201c<code><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"eb989e9b9b84999fab859b868198c5838e879b\">[email\u00a0protected]<\/a><\/code>.\u201d By the point he started eradicating the contaminated packages, entry to his account was misplaced. Some packages, like simple-swizzle, stay compromised as of the newest replace.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/09\/npm-packages-2-billion-downloads-hacked-attack-1.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"526\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/09\/npm-packages-2-billion-downloads-hacked-attack-1.jpg\" alt=\"npm Packages With 2 Billion Weekly Downloads Hacked in Major Attack\" class=\"wp-image-134537\" style=\"width:560px;height:auto\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/09\/npm-packages-2-billion-downloads-hacked-attack-1.jpg 900w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/09\/npm-packages-2-billion-downloads-hacked-attack-1-300x175.jpg 300w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/09\/npm-packages-2-billion-downloads-hacked-attack-1-768x449.jpg 768w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/09\/npm-packages-2-billion-downloads-hacked-attack-1-380x222.jpg 380w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/09\/npm-packages-2-billion-downloads-hacked-attack-1-800x468.jpg 800w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\"\/><\/a><\/figure>\n<\/div>\n<p>Aikido\u2019s evaluation shared with Hackread.com reveals the code is extremely intrusive, modifying features like <code>fetch<\/code>, <code>XMLHttpRequest<\/code>, and pockets API strategies. It alters transaction payloads, approvals, and even Solana\u2019s signing stream, redirecting property with out the person\u2019s information. In sensible phrases, this implies a developer who up to date one in all these packages could possibly be exposing customers to pockets hijacking as they work together with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/the-idea-of-web3-and-7-global-web3-agencies\/\" data-type=\"post\" data-id=\"116792\" target=\"_blank\" rel=\"noreferrer noopener\">Web3 functions<\/a>.<\/p>\n<p>For now, builders are suggested to roll again to identified protected variations, audit any current package deal updates, and monitor transactions carefully if their functions work together with cryptocurrency wallets. The state of affairs stays lively, and Aikido is now posting stay updates on its <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.aikido.dev\/blog\/npm-debug-and-chalk-packages-compromised\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">official weblog<\/a>.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="WzwkqIBeyjDnS1JBAkAh"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Aikido Safety flagged the most important npm assault ever recorded, with 18 packages like chalk, debug, and ansi-styles hacked to hijack crypto wallets by way of injected code. Aikido Safety has flagged what could possibly be the most important npm provide chain compromise ever recorded. The account of a long-trusted maintainer generally known as qix [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6463,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[717,1040,2916,173,967,1116,2987,5241],"class_list":["post-6461","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-attack","tag-billion","tag-downloads","tag-hacked","tag-major","tag-npm","tag-packages","tag-weekly"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6461"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6461\/revisions"}],"predecessor-version":[{"id":6462,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6461\/revisions\/6462"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/6463"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-21 07:58:33 UTC -->