A new security vulnerability threatens the crypto ecosystem and online services
Mar 09 Sep 2025 ▪ 4 min read
Get informed
▪
Scam
The crypto ecosystem has just suffered one of the most sophisticated attacks in its history. A 'crypto-clipper' injected through compromised NPM modules discreetly redirects wallet addresses during transactions. How could this breach escape security radars?
In summary
A recognized developer in the NPM ecosystem had their account compromised by phishing.
Ultra-popular JavaScript modules were infected by sophisticated malware.
The malicious code replaces crypto addresses with those of the attackers in real time.
Only hardware wallets offer effective protection against this attack.
The anatomy of a large-scale attack
On September 8, 2025, the crypto ecosystem was shaken by an unprecedented magnitude attack. In fact, a recognized developer responsible for widely used JavaScript libraries had their NPM account compromised after a simple phishing email. This access was enough to trigger a true digital storm.
NPM, the true backbone of the modern web, distributes over a billion code modules to developers around the world every week.
When a popular package like 'chalk', 'strip-ansi', or 'color-convert' is infected, the entire digital chain trembles. In a matter of hours, thousands of projects – websites, mobile applications, cloud services – become exposed.
$SOL $BNB #ecosistemacripto