Scan to download
BTC $74,981.60 +0.11%
ETH $2,337.21 -0.64%
BNB $628.87 +0.81%
XRP $1.43 +1.76%
SOL $88.15 +3.13%
TRX $0.3259 +0.13%
DOGE $0.0980 +1.54%
ADA $0.2553 +1.88%
BCH $448.89 +1.46%
LINK $9.44 +1.35%
HYPE $43.60 -3.93%
AAVE $113.41 +6.23%
SUI $0.9853 +0.78%
XLM $0.1660 +3.30%
ZEC $333.95 -2.87%
BTC $74,981.60 +0.11%
ETH $2,337.21 -0.64%
BNB $628.87 +0.81%
XRP $1.43 +1.76%
SOL $88.15 +3.13%
TRX $0.3259 +0.13%
DOGE $0.0980 +1.54%
ADA $0.2553 +1.88%
BCH $448.89 +1.46%
LINK $9.44 +1.35%
HYPE $43.60 -3.93%
AAVE $113.41 +6.23%
SUI $0.9853 +0.78%
XLM $0.1660 +3.30%
ZEC $333.95 -2.87%

Data: The attacker of the NPM developer account is currently suspected to have only profited about 20 dollars

2025-09-09 10:17:47
Collection

ChainCatcher news, according to CertiK Alert monitoring, the NPM account of developer Qix has been phished, with attackers injecting malicious code into npm. According to Security Alliance, the attackers seem to have profited only about 0.05 dollars worth of ETH and 20 dollars worth of Meme coins.

Earlier reports indicated that Ledger's Chief Technology Officer Charles Guillemet stated, "A large-scale supply chain attack is currently underway: the NPM account of a well-known developer has been compromised. The affected package has been downloaded over 1 billion times, which means the entire JavaScript ecosystem may be at risk. The malicious code works by silently altering cryptocurrency addresses in the background to steal funds."

app_icon
ChainCatcher Building the Web3 world with innovations.