Compromised – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 08 Sep 2025 19:17:58 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Compromised – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Largest supply chain attack in history targets crypto users through compromised JavaScript packages https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/ https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/#respond Mon, 08 Sep 2025 19:17:57 +0000 https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/

A new cyberattack is silently targeting crypto from users during transactions amid an incident that security researchers describe as the largest supply chain attack in history.

BleepingComputer reported that hackers compromised NPM package maintainer accounts through phishing emails and injected malware that steals crypto.

The attack targeted JavaScript developers with fraudulent emails appearing to originate from “[email protected],” an impersonated domain mimicking the legitimate NPM registry.

The phishing messages warned maintainers that their accounts would be locked on Sept. 10, unless they updated their two-factor authentication credentials through a malicious link.

Attackers successfully compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries include fundamental development tools such as “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting virtually the entire JavaScript ecosystem.

Targeting crypto

The malicious code operates as a browser-based interceptor, monitoring network traffic for crypto transactions across Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash networks.

When users initiate crypto transfers, the malware silently replaces destination wallet addresses with attacker-controlled accounts before transaction signing.

Aikido Security researcher Charlie Eriksen explained:

“What makes it dangerous is that it operates at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

Ledger CTO Charles Guillemet warned crypto users about the ongoing threat, noting the JavaScript ecosystem may be compromised given the massive download figures.

Hardware wallet users retain protection if they verify transaction details before signing, while software wallet users face a higher risk. Guillemet advised:

“If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.”

He also noted uncertainty about whether attackers can directly extract seed phrases from software wallets.

Sophisticated targeting

The attack represents a sophisticated supply chain targeting where criminals compromise trusted development infrastructure to reach end users.

By infiltrating packages downloaded billions of times weekly, attackers gained unprecedented access to cryptocurrency applications and wallet interfaces.

BleepingComputer identified the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows similar JavaScript library compromises throughout 2025, including the July attack on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten popular NPM libraries.

Mentioned in this article
]]>
https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/feed/ 0 57436
Cointelegraph and CoinMarketCap front ends compromised with scam links over the weekend https://earlybirdsinvest.com/cointelegraph-and-coinmarketcap-front-ends-compromised-with-scam-links-over-the-weekend/ https://earlybirdsinvest.com/cointelegraph-and-coinmarketcap-front-ends-compromised-with-scam-links-over-the-weekend/#respond Mon, 23 Jun 2025 08:35:40 +0000 https://earlybirdsinvest.com/cointelegraph-and-coinmarketcap-front-ends-compromised-with-scam-links-over-the-weekend/

Cointelegraph, one of the leading crypto media platforms, has confirmed a front-end security breach that exposed its users to a malicious pop-up urging them to connect their wallets.

The incident, which occurred on June 22, involved scammers promoting a fake Cointelegraph token (CTG) and a counterfeit initial coin offering (ICO) campaign.

Scam Sniffer, a blockchain security platform, first flagged the compromise, noting that the attackers aimed to deceive users into granting wallet access. Once connected, these wallets could be drained of assets.

Cointelegraph
Malicious Pop-Up on Cointelegraph (Source: Scam Sniffer)

Scam Sniffer traced the exploit to a JavaScript payload embedded via the site’s advertising infrastructure. The code appeared to come from a domain resembling AdButler, though it had been recently registered and linked to a malicious script hidden within a banner advertisement.

In a public statement, Cointelegraph acknowledged the issue and warned users not to interact with pop-ups promoting “CTG tokens” or “CoinTelegraph ICO airdrops.”

The platform emphasized that it is actively investigating and working to remove the malicious code. Users were advised not to enter personal details or connect wallets to any prompts on the site.

CoinMarketCap faced similar exploits

This incident follows a similar attack on CoinMarketCap just two days prior.

On June 20, the crypto data provider briefly experienced a front-end breach that resulted in a fake wallet prompt appearing on its homepage.

CoinMarketCap traced the vulnerability to a doodle image linked to unauthorized JavaScript, which briefly disrupted the site’s interface. It noted:

“Our security team identified a vulnerability related to a doodle image displayed on our homepage. This doodle image contained a link that triggered malicious code through an API call, resulting in an unexpected pop-up for some users when visited our homepage.”

While the message on each site differed, both cases followed a near-identical delivery mechanism: a deceptive pop-up disguised as a platform feature. This may indicate a coordinated campaign targeting high-traffic crypto websites using ad-based JavaScript exploits.

Security experts pointed out that the twin breaches highlight a growing trend of attackers exploiting trusted platforms to execute wallet-draining schemes. As a result, they urged crypto users to remain cautious, avoid interacting with unknown dApps, and regularly monitor wallet activity to stay safe.

Mentioned in this article
]]>
https://earlybirdsinvest.com/cointelegraph-and-coinmarketcap-front-ends-compromised-with-scam-links-over-the-weekend/feed/ 0 43615
JPMorgan Chase, Bank of America and TD Bank Issue Data Breach Alerts, Say Critical Information on Several Customers Compromised https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-td-bank-issue-data-breach-alerts-say-critical-information-on-several-customers-compromised/ https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-td-bank-issue-data-breach-alerts-say-critical-information-on-several-customers-compromised/#respond Sat, 14 Jun 2025 15:45:34 +0000 https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-td-bank-issue-data-breach-alerts-say-critical-information-on-several-customers-compromised/

JPMorgan Chase, Bank of America and TD Bank are disclosing data breaches that are placing some customers’ accounts and personal information at risk.

In new filings with the Massachusetts state government, Chase says at least four customers in the state are affected by multiple breaches.

In two incidents, Chase says employees improperly accessed customers’ credit and debit card information and triggered fraudulent transactions, prompting the bank to close the affected cards, issue replacements, and reimburse the customers.

In the other two incidents, the bank says it mistakenly posted transaction details, including names, addresses, account numbers, and transaction amounts, to other customers’ accounts. At this point, no misuse due to those errors has been detected.

Meanwhile, Bank of America says documentation relating to at least one customer’s savings bonds was lost in transit on February 14th.

Attempts to recover the documentation, according to the North Carolina-based lender, have proved unsuccessful.

“According to our records, the information involved in this incident was related to your Savings Bonds and included your first and last name, address, Social Security number, and account number.”

The lender says it is monitoring the customer’s banking account for any suspicious activity and is committed to resolving any unauthorized transactions.

Lastly, TD Bank says a former employee improperly accessed a customer’s personal information between December of 2024 and January of 2025.

The information may have included the customer’s name, address, phone number, social security number, account number, and transactional data.

TD Bank says it’s monitoring the account for fraud and is offering the customer a complimentary two year membership to an identity theft protection and recovery service.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/jpmorgan-chase-bank-of-america-and-td-bank-issue-data-breach-alerts-say-critical-information-on-several-customers-compromised/feed/ 0 42005
Fake Ledger Live App on macOS Steals Crypto—Over 2,800 Sites Compromised https://earlybirdsinvest.com/fake-ledger-live-app-on-macos-steals-crypto-over-2800-sites-compromised/ https://earlybirdsinvest.com/fake-ledger-live-app-on-macos-steals-crypto-over-2800-sites-compromised/#respond Sat, 24 May 2025 21:29:59 +0000 https://earlybirdsinvest.com/fake-ledger-live-app-on-macos-steals-crypto-over-2800-sites-compromised/

macOS users who use Ledger Live are being targeted by a scam that tricks them into handing over their crypto.

According to a report from Moonlock on May 22, attackers are spreading fake versions of the Ledger Live app that can steal wallet recovery phrases and empty users’ accounts.

The fake app replaces the official Ledger Live after a user’s computer is infected. Once installed, it shows a warning message that looks legitimate and asks the user to enter their seed phrase. If entered, that information is sent straight to the attacker, which allows them to take full control of the wallet.

How Can You Earn Money With Axie Infinity? (AXS Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Moonlock stated that the malware is often spread using a tool called Atomic macOS Stealer. The cybersecurity firm has found the tool on around 2,800 websites that have been compromised. When it infects a system, it collects personal info, passwords, wallet details, and then swaps out the real app for a fake one.

Initially, the fake app could only collect basic wallet data, like notes or password hints, but could not access the funds directly. However, Moonlock explained that attackers have figured out how to collect seed phrases, which allows them to transfer all the money out of the wallet.

Moonlock warns that this is not just about theft—it is about hackers finding new ways to target tools that many crypto users trust.

On May 11, a Ledger Discord moderator account was hacked and posted a phishing link requesting users’ wallet recovery phrases. How did Ledger respond? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/fake-ledger-live-app-on-macos-steals-crypto-over-2800-sites-compromised/feed/ 0 38116
Compromised Mod Account Hits Ledger Discord Server in Wallet Scam Attempt https://earlybirdsinvest.com/compromised-mod-account-hits-ledger-discord-server-in-wallet-scam-attempt/ https://earlybirdsinvest.com/compromised-mod-account-hits-ledger-discord-server-in-wallet-scam-attempt/#respond Tue, 13 May 2025 05:45:44 +0000 https://earlybirdsinvest.com/compromised-mod-account-hits-ledger-discord-server-in-wallet-scam-attempt/

On May 11, Ledger’s Discord server was briefly compromised after a moderator’s account was taken over, according to Ledger team member Quintin Boatwright.

The attacker used the account to share a fake link and claimed that users were required to confirm their wallet recovery phrases. The message was designed to trick people into handing over access to their crypto wallets.

Screenshots shared on X show that the fake message warned of a “security issue” and urged users to act quickly by clicking a link. Anyone who followed it was asked to connect their wallet and complete several steps, which included sharing sensitive information.

What is a Crypto Wallet? (Explained With Animation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Ledger’s team responded by removing the compromised moderator account and deleting the bot used to spread the link. They also took down the website the link pointed to and reviewed all channel permissions to prevent further abuse.

An X user said in a May 11 post on X that they were banned or muted while trying to report the incident, which may have delayed the team’s response.

According to Boatwright, “the issue was quickly contained”, and new steps have been taken to improve Discord security. He also confirmed that this was a one-time incident and that the attack was limited to the Discord channel.

On April 29, scammers targeted Ledger wallet owners by sending fake Ledger letters through the mail. How did the company respond? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/compromised-mod-account-hits-ledger-discord-server-in-wallet-scam-attempt/feed/ 0 35935