List of Flash News about NPM supply chain attack
Time | Details |
---|---|
2025-09-09 14:15 |
NPM Supply Chain Attack Aftershocks: Crypto Market Sentiment Dips, Less Than $500 Stolen Despite 2 Billion Weekly Downloads
According to @cookiedotfun, most projects showing Bad Sentiment today were linked to the recent NPM supply chain attack based on signals in their profiles' Latest Buzz sections (source: Cookie DAO on X, Sep 9, 2025). Cookie DAO detailed that the incident involved malicious code injected into NPM packages and noted a rapid containment by security researchers and the NPM security team (source: Cookie DAO on X, Sep 9, 2025). Early figures shared by Cookie DAO indicate affected packages collectively see over 2 billion weekly downloads, yet confirmed direct financial losses were under $500, implying limited immediate on-chain damage for crypto projects (source: Cookie DAO on X, Sep 9, 2025). Cookie DAO also reported that multiple crypto projects publicly confirmed no impact, with overall exposure limited despite short-term sentiment pressure (source: Cookie DAO on X, Sep 9, 2025). |
2025-09-09 02:15 |
NPM Supply Chain Attack: Malicious Code in 1B+ Downloads Swaps Crypto Addresses, Traders Urged to Avoid On-Chain Activity
According to @rovercrc, a compromised NPM account injected malicious code into widely used packages with more than 1 billion cumulative downloads, indicating an active software supply chain attack (source: @rovercrc on X, Sep 9, 2025). The malware reportedly swaps crypto addresses to redirect funds and may also target software wallets, creating direct theft risk during transactions (source: @rovercrc on X, Sep 9, 2025). The source advises hardware wallet users to double-check every transaction before signing and recommends non-hardware wallet users avoid on-chain transactions for now (source: @rovercrc on X, Sep 9, 2025). For traders, this advisory signals heightened operational risk for on-chain executions and wallet interactions until the compromised packages are identified and remediated (source: @rovercrc on X, Sep 9, 2025). |
2025-09-08 21:02 |
Santiment: 5 Must-Watch Crypto Catalysts — NPM Supply Chain Attack, CPI/PPI, Worldcoin (WLD) Treasury, Nasdaq Tokenized Stocks, Solana (SOL) Memecoins
According to @santimentfeed, a major NPM supply chain attack injected address-swapping malware into popular JavaScript packages, prompting Ledger’s CTO to urge avoiding on-chain transactions unless using hardware wallets with strict verification, elevating multi-chain theft risk for traders (Source: Santiment @santimentfeed). According to @santimentfeed, this week’s macro slate includes U.S. non-farm payroll revisions, PPI, CPI, and the ECB rate decision, with crypto starting strong on institutional buying and hopes for Fed cuts, making inflation prints pivotal for near-term price action (Source: Santiment @santimentfeed). According to @santimentfeed, Eightco Holdings (OCTO) announced a $250M private placement to launch the first Worldcoin (WLD) treasury strategy, with BitMine and Tom Lee contributing $20M, driving OCTO up over 3,000% and WLD up 40%+, while Dan Ives was named chairman, signaling institutional interest in crypto treasuries (Source: Santiment @santimentfeed). According to @santimentfeed, Nasdaq filed with the SEC to enable trading of tokenized stocks and ETFs on blockchain with equal priority to traditional listings, a potential market structure shift if approved that aligns with growing demand for regulated digital securities (Source: Santiment @santimentfeed). According to @santimentfeed, Solana (SOL) and memecoins like USELESS, BONK, and FARTCOIN are gaining momentum with SOL nearing ATHs, aided by Lion Group moving SOL and SUI to Hyperliquid (HYPE) as HYPE hits a new ATH amid stablecoin and protocol upgrade news (Source: Santiment @santimentfeed). |