📈 Get daily crypto insights that make you smarter about your money

September 2025 NPM Supply Chain Breach Drains Crypto Wallets Via Address Swap Malware

The JavaScript ecosystem suffered one of its most devastating supply chain attacks in September 2025, as threat actors compromised at least 27 NPM packages through a sophisticated phishing campaign, injecting cryptocurrency-stealing malware that targeted wallets across six blockchains. The breach, first detected on September 8, sent shockwaves through the developer community as the full scope of the attack became clear over the following days.

The Exploit Mechanics

The attack began with a meticulously crafted phishing campaign. Attackers registered the domain npmjs.help on September 4, 2025, creating a near-perfect impersonation of NPM’s official infrastructure. Phishing emails were dispatched to multiple high-profile package maintainers on September 8, claiming urgent two-factor authentication updates were required by September 10.

Josh Junon, a maintainer of critical JavaScript infrastructure packages, recounted the attack vector: the email appeared to come from [email protected] and looked legitimate at first glance. Operating on mobile during a stressful morning, the maintainer clicked the phishing link rather than navigating directly to the NPM website.

Once inside, the attackers published malicious versions of the compromised packages. The injected malware demonstrated advanced obfuscation techniques using hexadecimal encoding and complex function structures. The code operated exclusively in browser environments, targeting cryptocurrency transactions through three primary mechanisms: API hooking that intercepted window.ethereum, fetch, and XMLHttpRequest calls; address replacement using Levenshtein distance algorithms to generate visually similar wallet addresses; and multi-chain support targeting Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash. The malware maintained over 280 hardcoded attacker addresses for redundancy.

Affected Systems

The scale of the compromise was staggering. At least 27 packages were confirmed compromised, affecting billions of weekly downloads across the JavaScript ecosystem. The affected packages included widely-used libraries such as chalk, ansi-regex, supports-color, strip-ansi, debug, duckdb, and prebid.js.

Fifteen packages required upgrades to newly published fixed versions, while twelve packages needed to be reverted to previous safe versions. The browser-only execution of the malware meant server-side Node.js applications were not directly affected, though the potential for future server-targeting variants remains a critical concern for infrastructure teams.

With Bitcoin trading at approximately $115,500 and Ethereum near $4,460 on September 11, the financial stakes of any successful wallet compromise were substantial. Even a small percentage of users executing transactions through compromised browsers could result in millions of dollars in stolen funds.

The Mitigation Strategy

NPM’s security team began removing malicious packages immediately upon detection, with the initial wave of compromised versions unpublished from the registry within hours. The incident response escalated through September 9 to 11, as security researchers continued discovering additional affected libraries. CVE assignments began for the most critical packages, and maintainers worked around the clock to regain control and publish fixes.

Organizations were advised to take immediate action: identify all affected packages using vulnerability scanning tools, update the fifteen packages with available fixes or revert the twelve packages to their last known safe versions, clear all NPM caches with npm cache clean --force, and verify package integrity against known-good checksums.

Lessons Learned

This attack underscores several critical vulnerabilities in the open-source software supply chain. First, the reliance on email-based authentication for package maintainers creates a single point of failure. Second, the sheer download volume of popular packages means even brief exposure windows can affect millions of users. Third, the targeting of cryptocurrency transactions through browser-based malware represents an evolution in financially-motivated supply chain attacks.

The attack also highlights the tension between developer convenience and security. Maintainers managing dozens of packages under time pressure are precisely the targets most susceptible to well-crafted phishing campaigns. Organizations must implement automated dependency scanning and pin package versions to known-good releases rather than using floating version specifiers.

User Action Required

If you used any affected NPM packages between September 8 and September 11, 2025, immediately audit your dependency tree, update all packages to their latest patched versions, and review any cryptocurrency transactions executed during this window for signs of address tampering. Enable hardware wallet verification for all high-value transfers, and consider using dedicated browser profiles for cryptocurrency operations that exclude development tooling.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified security professionals regarding your specific infrastructure needs.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “September 2025 NPM Supply Chain Breach Drains Crypto Wallets Via Address Swap Malware”

  1. the fact that one maintainer clicking a phishing link on mobile took down 27 packages is insane. npm needs mandatory hardware keys for anything with over 1M weekly downloads

    1. npm_orphan_42 mandatory hardware keys for high-download packages is the only answer. one maintainer on mobile shouldnt be able to compromise the entire JS ecosystem

      1. Yelena V. hardware keys for top packages is the only fix. one maintainer clicking a phishing link on mobile shouldnt be able to drain wallets across 6 chains

        1. dep_tree_horror npm still doesnt enforce 2FA on publish for packages doing millions of weekly downloads. the registry is the weak link, not individual devs

          1. pkg_lockdown_ npm still does not enforce 2FA on publish for packages doing millions of weekly downloads. sigstore was proposed in 2022 and is still not mandatory. the ecosystem learned nothing from this

    1. real yield protocols are great until a compromised npm package swaps your withdrawal address. the attack surface shifted not disappeared

  2. six chains affected and people still connect their main wallet to dapps without a hardware key. this attack was sophisticated but the next one will be simpler and bigger

  3. 280 hardcoded attacker addresses across 6 blockchains and the malware was live for days. npmjs.help registered sep 4 and nobody flagged it until sep 8. DNS monitoring for typo-squats of major registries should be table stakes by now

  4. 27 packages compromised through one phishing domain and npm still has no mandatory code review for dependency changes over 50 lines. the trust model is one maintainer on a phone

    1. TVL recovery is real but this was a supply chain attack not a DeFi bug. completely different threat model

      1. lena is right that the threat model is different. defi insurance wont help you if your wallet signs a transaction to a swapped address from a compromised npm package

  5. 27 packages compromised through one phishing domain. the npm ecosystem needs signed package verification yesterday. every JS project is one maintainer phishing click away from disaster

    1. pkg_audit_ said the 4 day gap shouldve been caught but by who? npm has no real security team monitoring domain registrations. the whole ecosystem runs on volunteer trust

      1. Greta W. npm has no security team because the registry runs on venture capital and goodwill. package signing has been proposed since 2018 and nothing shipped

        1. domain_squat_watcher

          sigpipe_zk_ npm has no security team because OpenJS Foundation runs on $5M a year in donations. the registry handles 2 billion package downloads weekly with the budget of a medium startup

  6. 280 hardcoded attacker addresses across 6 chains and the malware was live for days. npmjs.help registered sep 4, attack sep 8, that 4 day gap shouldve been caught

    1. 4 day gap between domain registration and attack is actually fast for threat actors. the phishing emails went out the same morning as registration in some cases

  7. The npmjs.help phishing domain was so convincing. Nearly fell for it myself during that stressful morning.

  8. cyber_defender

    These supply chain attacks show how fragile the entire npm ecosystem is. One phishing email compromises thousands of projects.

  9. Domain impersonation is getting so sophisticated. Need better verification systems for package maintainers.

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,791.00-0.2%ETH$1,916.14+0.2%SOL$76.24+2.1%BNB$602.39+1.3%XRP$1.04+0.3%ADA$0.1993+0.1%DOGE$0.0701-0.1%DOT$0.8110-0.7%AVAX$6.48-0.6%LINK$8.33+1.2%UNI$3.97-0.4%ATOM$1.38+0.5%LTC$46.04+1.1%ARB$0.0778-1.0%NEAR$1.63+2.6%FIL$0.7110+1.7%SUI$0.6917+1.4%BTC$64,791.00-0.2%ETH$1,916.14+0.2%SOL$76.24+2.1%BNB$602.39+1.3%XRP$1.04+0.3%ADA$0.1993+0.1%DOGE$0.0701-0.1%DOT$0.8110-0.7%AVAX$6.48-0.6%LINK$8.33+1.2%UNI$3.97-0.4%ATOM$1.38+0.5%LTC$46.04+1.1%ARB$0.0778-1.0%NEAR$1.63+2.6%FIL$0.7110+1.7%SUI$0.6917+1.4%
Scroll to Top