Wednesday, September 10, 2025
No Result
View All Result
Crypto Waffle
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
No Result
View All Result
Crypto Waffle
No Result
View All Result

NPM Attack: Javascript Library Compromise Goes After Bitcoin Wallets

September 8, 2025
in Bitcoin
Reading Time: 2 mins read
0 0
A A
0
Home Bitcoin
Share on FacebookShare on Twitter


A major NPM developer, qix, has had their account compromised. It was used to push malware that targets and searches for bitcoin and cryptocurrency wallets on users devices. If detected, the malware would patch the code functions used to coordinate transaction signing, and replace the address a user is trying to send money to with one of the malware creator’s own addresses.

This should mostly be a concern for web wallet users, so in the Bitcoin ecosystem Ordinals or Runes/other token users, as unless an update for your normal software wallet happened to be pushed just earlier today with the compromised dependency, or if your wallet dynamically loads code directly from the wallet back end bypassing the app-store, you should be fine.

NPM is a package manager for Node.js, a popular Javascript framework. This means it is used to grab large sets of pre-written code used for common functionality to be integrated into different programs without the developer having to rewrite basic functions themselves.

The targeted packages were not cryptocurrency specific, but packages used by countless numbers of normal applications built with Node.js, not just cryptocurrency wallets.

If you are using a hardware wallet in combination with your web wallet, take extra care to verify on the device itself that the destination address you are sending too is correct before signing anything.

If you are using software keys in the web wallet itself, it would be advisable to not open them or transact until you are certain you are not running a vulnerable version of the wallet. The safest course of action would be waiting for an announcement from the team developing the wallet you use.



Source link

Tags: attackBitcoinCompromisejavascriptLibraryNPMWallets
Previous Post

Pundit Says ‘Ethereum Is Dying’ As Fundamentals Collapse By Over 40% — Details | Bitcoinist.com

Next Post

Ethereum Marches Upward Without Leverage Overheating – Sign Of Structural Health?

Related Posts

QMMM Stock Skyrockets 1,730% After Announcing 0 Million Crypto Treasury
Bitcoin

QMMM Stock Skyrockets 1,730% After Announcing $100 Million Crypto Treasury

September 10, 2025
XRP瑞波幣即時新聞:有望實現三倍增長動態更新(9月10日)
Bitcoin

XRP瑞波幣即時新聞:有望實現三倍增長動態更新(9月10日)

September 10, 2025
You Cannot Stop Bitcoin Metaprotocols
Bitcoin

You Cannot Stop Bitcoin Metaprotocols

September 9, 2025
Bitcoin Above Key Trendline But Below ATH – Is The Next Rally Loading?
Bitcoin

Bitcoin Above Key Trendline But Below ATH – Is The Next Rally Loading?

September 9, 2025
Bitcoin ETFs Pull in 8 Million as Ether Funds Log Sixth Day of Exits
Bitcoin

Bitcoin ETFs Pull in $368 Million as Ether Funds Log Sixth Day of Exits

September 9, 2025
Robinhood Summit 2025: Agenda, Livestream, Product Reveals, and the Crypto Roadmap
Bitcoin

Robinhood Summit 2025: Agenda, Livestream, Product Reveals, and the Crypto Roadmap

September 9, 2025
Next Post
Ethereum Marches Upward Without Leverage Overheating – Sign Of Structural Health?

Ethereum Marches Upward Without Leverage Overheating - Sign Of Structural Health?

Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

Binance Unveils AI-Powered Features to Help Traders Navigate Crypto Markets

Binance Unveils AI-Powered Features to Help Traders Navigate Crypto Markets

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • USD
  • EUR
  • GBP
  • AUD
  • JPY
  • bitcoinBitcoin(BTC)
    $112,280.00
  • ethereumEthereum(ETH)
    $4,330.13
  • rippleXRP(XRP)
    $2.97
  • tetherTether(USDT)
    $1.00
  • binancecoinBNB(BNB)
    $884.16
  • solanaSolana(SOL)
    $220.26
  • usd-coinUSDC(USDC)
    $1.00
  • staked-etherLido Staked Ether(STETH)
    $4,323.42
  • dogecoinDogecoin(DOGE)
    $0.240467
  • tronTRON(TRX)
    $0.337195
Facebook Twitter Instagram Youtube RSS
Crypto Waffle

Your go-to source for the freshest cryptocurrency news, in-depth analysis, market trends, and expert insights.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Web3

SITEMAP

  • About us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin(BTC)$112,280.00-0.45%
  • ethereumEthereum(ETH)$4,330.13-0.51%
  • rippleXRP(XRP)$2.97-1.52%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$884.160.18%
  • solanaSolana(SOL)$220.261.17%
  • usd-coinUSDC(USDC)$1.000.00%
  • staked-etherLido Staked Ether(STETH)$4,323.42-0.48%
  • dogecoinDogecoin(DOGE)$0.240467-0.42%
  • tronTRON(TRX)$0.3371950.04%

Powered by
...
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by