logo

Security Advisory: Another well-known developer's NPM account has been compromised, injecting wallet-stealing malware

By: theblockbeats.news|2025/09/09 16:02:41

BlockBeats News, September 9th. According to Socket monitoring, the ongoing NPM supply chain attack has spread from the well-known developer Qix to another highly prominent maintainer. The NPM account duckdb_admin, responsible for the DuckDB-related package, has been compromised, and multiple malicious versions have been published. The injected code is the same wallet-stealing malware used when Qix's account was compromised, strongly indicating that both are part of the same attack campaign.


Previously reported, Ledger's CTO stated that in the event of a large-scale supply chain attack, the entire JavaScript ecosystem could be at risk. However, the NPM attackers were not successful, and there were almost no victims.

Analyst: Revisions to Employment Data Further Fuel Speculation of Fed Rate Cut
Frax: USDH Buyback Ratio to Be Determined by the Community, Ecosystem Data to Remain Transparent

You may also like

Share
copy

Gainers

Latest Crypto News

01:15

「Whale」 Ethereum Multi-Step again Partially Liquidated, Account Balance Fell Below $270,000

01:15

Cryptocurrency Fear and Greed Index Drops to 24, Market Enters "Extreme Fear" Mode Again

01:15

「Cool-headed King of Shorting」 entered a new MON short position, earlier this morning closed a long position on BTC and SOL before reversing to open a short position

01:15

In the past 4 hours, the entire network has seen $435 million in liquidations, with longs accounting for $424 million of the total.

01:15

「CZ's Countertrade」 Long Position's Unrealized Loss Expands to $26 Million, Now the Largest Long on Hyperliquid for ETH and XRP

Read more
Community
icon
icon
icon
icon
icon
icon
icon
icon

Customer Support@weikecs

Business Cooperation@weikecs

Quant Trading & MM[email protected]

VIP Services[email protected]