logo

Security Advisory: Another well-known developer's NPM account has been compromised, injecting wallet-stealing malware

By: theblockbeats.news|2025/09/09 16:02:41

BlockBeats News, September 9th. According to Socket monitoring, the ongoing NPM supply chain attack has spread from the well-known developer Qix to another highly prominent maintainer. The NPM account duckdb_admin, responsible for the DuckDB-related package, has been compromised, and multiple malicious versions have been published. The injected code is the same wallet-stealing malware used when Qix's account was compromised, strongly indicating that both are part of the same attack campaign.


Previously reported, Ledger's CTO stated that in the event of a large-scale supply chain attack, the entire JavaScript ecosystem could be at risk. However, the NPM attackers were not successful, and there were almost no victims.

WEEX se dirige a Blockchain Life Dubai 2025
El mayor acuerdo comercial impulsa el aumento de Bitcoin: 5 ideas clave para esta semana en el mundo de las criptomonedas

También te puede interesar

Compartir
copy

Ganadores

Últimas noticias sobre criptomonedas

01:20

Alliance DAO Genesis: It is hard to convince oneself to hold the L1 token long term, as there is no "Moat."

01:18

On-Chain Whale Activity Overview: 'Buddy' Adds to Long Position, Whale Nets Over $10 Million in Profits Shorting 1000 BTC

23:18

YZi Labs has submitted a draft registration statement to the U.S. SEC, intending to expand the CEA Industries board and elect new directors.

07:03

24-Hour Spot Funding Flow Leaderboard: BTC Net Inflow of $473 Million, ETH Net Outflow of $33.22 Million

07:01

A whale has ended a nearly 3-year hibernation, selling 200 BTC.

Leer más
Comunitario
icon
icon
icon
icon
icon
icon
icon

Atención al cliente@weikecs

Cooperación empresarial@weikecs

Trading cuantitativo y MM[email protected]

Programa VIP[email protected]