• bitcoinBitcoin (BTC) $ 111,651.00
  • ethereumEthereum (ETH) $ 3,960.72
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.62
  • bnbBNB (BNB) $ 1,114.55
  • usd-coinUSDC (USDC) $ 0.999858
  • staked-etherLido Staked Ether (STETH) $ 3,961.15
  • dogecoinDogecoin (DOGE) $ 0.197846
  • tronTRON (TRX) $ 0.297851
  • cardanoCardano (ADA) $ 0.658733
  • wrapped-stethWrapped stETH (WSTETH) $ 4,805.76
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 111,343.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,253.34
  • chainlinkChainlink (LINK) $ 18.11
  • hyperliquidHyperliquid (HYPE) $ 42.78
  • wrapped-eethWrapped eETH (WEETH) $ 4,257.61
  • ethena-usdeEthena USDe (USDE) $ 0.998011
  • stellarStellar (XLM) $ 0.327279
  • bitcoin-cashBitcoin Cash (BCH) $ 508.13
  • suiSui (SUI) $ 2.56
  • usdsUSDS (USDS) $ 1.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • wethWETH (WETH) $ 3,941.10
  • avalanche-2Avalanche (AVAX) $ 19.66
  • leo-tokenLEO Token (LEO) $ 9.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 111,488.00
  • litecoinLitecoin (LTC) $ 96.79
  • hedera-hashgraphHedera (HBAR) $ 0.173220
  • usdt0USDT0 (USDT0) $ 0.998865
  • moneroMonero (XMR) $ 335.68
  • whitebitWhiteBIT Coin (WBT) $ 42.48
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • crypto-com-chainCronos (CRO) $ 0.152633
  • the-open-networkToncoin (TON) $ 2.16
  • mantleMantle (MNT) $ 1.67
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • daiDai (DAI) $ 1.00
  • polkadotPolkadot (DOT) $ 3.09
  • zcashZcash (ZEC) $ 274.55
  • memecoreMemeCore (M) $ 2.26
  • bittensorBittensor (TAO) $ 391.33
  • uniswapUniswap (UNI) $ 6.26
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.136907
  • okbOKB (OKB) $ 167.03
  • aaveAave (AAVE) $ 227.53
  • susdssUSDS (SUSDS) $ 1.07
  • ethenaEthena (ENA) $ 0.466329
  • bitget-tokenBitget Token (BGB) $ 4.69
  • pepePepe (PEPE) $ 0.000007
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.29
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.215221
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 240.39
  • solanaWrapped SOL (SOL) $ 194.05
  • ethereum-classicEthereum Classic (ETC) $ 16.03
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,962.21
  • aptosAptos (APT) $ 3.31
  • ondo-financeOndo (ONDO) $ 0.737954
  • aster-2Aster (ASTER) $ 1.14
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.51
  • falcon-financeFalcon USD (USDF) $ 0.999219
  • tether-goldTether Gold (XAUT) $ 4,120.52
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.196587
  • worldcoin-wldWorldcoin (WLD) $ 0.892108
  • usdtbUSDtb (USDTB) $ 0.995753
  • gatechain-tokenGate (GT) $ 15.50
  • arbitrumArbitrum (ARB) $ 0.321202
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,517.96
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 13.28
  • pi-networkPi Network (PI) $ 0.207545
  • binance-staked-solBinance Staked SOL (BNSOL) $ 209.20
  • hash-2Provenance Blockchain (HASH) $ 0.033724
  • story-2Story (IP) $ 5.26
  • internet-computerInternet Computer (ICP) $ 3.13
  • algorandAlgorand (ALGO) $ 0.186371
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 42.82
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,164.76
  • chainopera-aiChainOpera AI (COAI) $ 7.83
  • cosmosCosmos Hub (ATOM) $ 3.17
  • vechainVeChain (VET) $ 0.017372
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,161.16
  • kaspaKaspa (KAS) $ 0.054912
  • pump-funPump.fun (PUMP) $ 0.004086
  • wbnbWrapped BNB (WBNB) $ 1,114.99
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,197.07
  • skySky (SKY) $ 0.058603
  • jupiter-exchange-solanaJupiter (JUP) $ 0.431785
  • pax-goldPAX Gold (PAXG) $ 4,108.69
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.021755
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 111,687.00
  • bfusdBFUSD (BFUSD) $ 0.999891
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • flare-networksFlare (FLR) $ 0.017037
  • render-tokenRender (RENDER) $ 2.49
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,188.47
  • sei-networkSei (SEI) $ 0.200830
  • official-trumpOfficial Trump (TRUMP) $ 6.00
  • bonkBonk (BONK) $ 0.000015
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999903
  • nexoNEXO (NEXO) $ 1.14
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 110,716.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.062846
  • filecoinFilecoin (FIL) $ 1.57
  • morphoMorpho (MORPHO) $ 2.02
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.10
  • immutable-xImmutable (IMX) $ 0.540598
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.992668
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,269.15
  • spx6900SPX6900 (SPX) $ 1.05
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 222.59
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.69
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 110,914.00
  • celestiaCelestia (TIA) $ 1.05
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.32
  • clbtcclBTC (CLBTC) $ 111,240.00
  • optimismOptimism (OP) $ 0.450095
  • aerodrome-financeAerodrome Finance (AERO) $ 0.938117
  • doublezeroDoubleZero (2Z) $ 0.240332
  • injective-protocolInjective (INJ) $ 8.47
  • lido-daoLido DAO (LDO) $ 0.924360
  • blockstackStacks (STX) $ 0.452550
  • msolMarinade Staked SOL (MSOL) $ 258.74
  • fasttokenFasttoken (FTN) $ 1.87
  • ousgOUSG (OUSG) $ 113.06
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.87
  • curve-dao-tokenCurve DAO (CRV) $ 0.536407
  • flokiFLOKI (FLOKI) $ 0.000074
  • plasmaPlasma (XPL) $ 0.376051
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,963.69
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 4,167.67
  • the-graphThe Graph (GRT) $ 0.065144
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998875
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.260729
  • pyth-networkPyth Network (PYTH) $ 0.116271
  • tbtctBTC (TBTC) $ 111,125.00
  • tezosTezos (XTZ) $ 0.608848
  • kaiaKaia (KAIA) $ 0.108694
  • sonic-3Sonic (S) $ 0.167037
  • humanityHumanity (H) $ 0.334198
  • iotaIOTA (IOTA) $ 0.149366
  • gtethGTETH (GTETH) $ 3,951.06
  • stader-ethxStader ETHx (ETHX) $ 4,224.89
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,941.07
  • beldexBeldex (BDX) $ 0.078636
  • usdaiUSDai (USDAI) $ 1.01
  • ether-fiEther.fi (ETHFI) $ 1.03
  • newton-projectAB (AB) $ 0.006903
  • conflux-tokenConflux (CFX) $ 0.110987
  • myx-financeMYX Finance (MYX) $ 2.91
  • theta-tokenTheta Network (THETA) $ 0.548688
  • usual-usdUsual USD (USD0) $ 0.996726
  • dogwifcoindogwifhat (WIF) $ 0.549122
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 1.00
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999810
  • pendlePendle (PENDLE) $ 3.21
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,345.13
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.28
  • swethSwell Ethereum (SWETH) $ 4,347.84
  • the-sandboxThe Sandbox (SAND) $ 0.214308
  • dashDash (DASH) $ 41.84
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 111,690.00
  • starknetStarknet (STRK) $ 0.120444
  • jasmycoinJasmyCoin (JASMY) $ 0.010725
  • galaGALA (GALA) $ 0.011192
  • ethereum-name-serviceEthereum Name Service (ENS) $ 15.59
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.197800
  • bittorrentBitTorrent (BTT) $ 0.00000050
  • true-usdTrueUSD (TUSD) $ 0.995783
  • raydiumRaydium (RAY) $ 1.79
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,936.53
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • vaultaVaulta (A) $ 0.294405
  • usddUSDD (USDD) $ 1.00
  • decentralandDecentraland (MANA) $ 0.242524
  • swissborgSwissBorg (BORG) $ 0.473758
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 24.16
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,251.16
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,178.09
  • jito-governance-tokenJito (JTO) $ 1.15
  • flowFlow (FLOW) $ 0.273549
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,267.59
  • syrupMaple Finance (SYRUP) $ 0.385784
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.11
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,959.94
  • sun-tokenSun Token (SUN) $ 0.022385
  • bitcoin-svBitcoin SV (BSV) $ 21.54
  • havvenSynthetix (SNX) $ 1.24
  • wrapped-hypeWrapped HYPE (WHYPE) $ 42.63
  • satoshi-stablecoinSatoshi Stablecoin (SATUSD) $ 1.00
  • zoraZora (ZORA) $ 0.094194
  • apecoinApeCoin (APE) $ 0.450966
  • ghoGHO (GHO) $ 0.999688

Ethereum, Solana Wallets Targeted in Massive ‘npm’ Attack But Just 5 Cents Taken

0 19

Ethereum, Solana Wallets Targeted in Massive 'npm' Attack But Just 5 Cents Taken

A phishing email on Monday took down one of Node.js’s most prolific developers by pushing malicious code into packages downloaded billions of times a week, in what researchers call the largest software supply-chain attack in recent times.

While the scope of the attack is massive, Security Alliance said in a Tuesday report that the attacker walked away with barely a few cents. However, security teams now face the substantial cost of updating backend systems to counter further attacks.

A very popular maintainer whose work (like chalk and debug-js) gets used in billions of downloads every week, known as “qix,” responsible for libraries such as chalk and debug-js, was compromised last week after receiving an email from support@npmjs[.]help. The domain once pointed to a Russian server and redirected to a spoofed two-factor authentication page hosted on the content delivery network BunnyCDN.

The credential stealer harvested username, password, and 2FA codes before sending them to a remote host. With full access, the attacker republished every qix package with a crypto-focused payload.

Node Package Manager (shortened to npm, not NPM) is like an app store for developers and is where coders download little building blocks of code (called packages) instead of writing everything from scratch. A maintainer is the person or entity who creates and updates those packages.

How the attack happened

The injected code was simple. It checked if window.ethereum was present and, if so, hooked into Ethereum’s core transaction functions. Calls to approve, permit, transfer, or transferFrom were silently rerouted to a single wallet, “0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976.”

Any Ethereum transaction with value and no data was also redirected. For Solana, the malware overwrote recipients with an invalid string beginning “1911…,” breaking transfers outright.

Network requests were also intercepted.

By hijacking fetch and XMLHttpRequest, the malware scanned JSON responses for substrings resembling wallet addresses and replaced them with one of 280 hardcoded alternatives to look deceptively similar.

Impact of the attack

But for all the distribution, the impact was negligible.

On-chain data shows the attacker received only around five cents of ether and about $20 worth of an illiquid memecoin that traded less than $600 in volume, the Security Alliance report said.

Popular browser wallet MetaMask also said on X that it was not affected by the npm supply chain attack as the wallet locks its code versions, uses manual and automated checks, and releases updates in stages. It also employs “LavaMoat,” which blocks malicious code even if inserted, and “Blockaid,” which rapidly flags compromised wallet addresses, to keep such attacks at bay.

Meanwhile, Ledger CTO Charles Guillemet warned that the malicious code had been pushed into packages with over a billion downloads and was designed to silently replace wallet addresses in transactions.

The attack follows another case flagged last week by ReversingLabs, where npm packages used Ethereum smart contracts to conceal malware links — a technique that disguised command-and-control traffic as ordinary blockchain calls.

Source

Leave A Reply

Your email address will not be published.