packages – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 08 Sep 2025 19:17:58 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 packages – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Largest supply chain attack in history targets crypto users through compromised JavaScript packages https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/ https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/#respond Mon, 08 Sep 2025 19:17:57 +0000 https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/

A new cyberattack is silently targeting crypto from users during transactions amid an incident that security researchers describe as the largest supply chain attack in history.

BleepingComputer reported that hackers compromised NPM package maintainer accounts through phishing emails and injected malware that steals crypto.

The attack targeted JavaScript developers with fraudulent emails appearing to originate from “[email protected],” an impersonated domain mimicking the legitimate NPM registry.

The phishing messages warned maintainers that their accounts would be locked on Sept. 10, unless they updated their two-factor authentication credentials through a malicious link.

Attackers successfully compromised 18 widely-used JavaScript packages with collective weekly downloads exceeding 2.6 billion.

The compromised libraries include fundamental development tools such as “chalk” (300 million weekly downloads), “debug” (358 million), and “ansi-styles” (371 million), affecting virtually the entire JavaScript ecosystem.

Targeting crypto

The malicious code operates as a browser-based interceptor, monitoring network traffic for crypto transactions across Ethereum, Bitcoin, Solana, Tron, Litecoin, and Bitcoin Cash networks.

When users initiate crypto transfers, the malware silently replaces destination wallet addresses with attacker-controlled accounts before transaction signing.

Aikido Security researcher Charlie Eriksen explained:

“What makes it dangerous is that it operates at multiple layers: altering content shown on websites, tampering with API calls, and manipulating what users’ apps believe they are signing.”

Ledger CTO Charles Guillemet warned crypto users about the ongoing threat, noting the JavaScript ecosystem may be compromised given the massive download figures.

Hardware wallet users retain protection if they verify transaction details before signing, while software wallet users face a higher risk. Guillemet advised:

“If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.”

He also noted uncertainty about whether attackers can directly extract seed phrases from software wallets.

Sophisticated targeting

The attack represents a sophisticated supply chain targeting where criminals compromise trusted development infrastructure to reach end users.

By infiltrating packages downloaded billions of times weekly, attackers gained unprecedented access to cryptocurrency applications and wallet interfaces.

BleepingComputer identified the phishing infrastructure exfiltrating credentials to “websocket-api2.publicvm.com,” demonstrating the coordinated nature of the operation.

This incident follows similar JavaScript library compromises throughout 2025, including the July attack on “eslint-config-prettier,” which had 30 million weekly downloads, and March compromises affecting ten popular NPM libraries.

Mentioned in this article
]]>
https://earlybirdsinvest.com/largest-supply-chain-attack-in-history-targets-crypto-users-through-compromised-javascript-packages/feed/ 0 57436
Hackers Use Ethereum Smart Contracts to Mask Malware in NPM Packages https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/ https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/#respond Sat, 06 Sep 2025 22:44:13 +0000 https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/

Hackers have discovered a new method for spreading malicious software by using Ethereum
ETH


$4,272.56

smart contracts to conceal crucial aspects of their attacks.

According to a blog post by Lucija Valentić at ReversingLabs, two suspicious software packages were found on the Node Package Manager (NPM), a platform used to share JavaScript code.

These packages, named “colortoolsv2” and “mimelib2“, were uploaded in July and designed to look like regular tools.

What is a Crypto Mining Pool? Is it Worth it? (Beginner-Friendly)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The packages acted like simple downloaders. When someone installed one, it would reach out to the Ethereum blockchain and fetch data from a smart contract. That data contained the location of a second piece of malware, which would then be downloaded and installed.

This made it hard for security systems to flag the packages as harmful, since they did not include any direct links to malicious websites or files.

Valentić explained that while Ethereum contracts have been misused before, this setup was different. In this case, the smart contract did not hold the malware itself, but held the location where it could be found.

The campaign was not limited to NPM. It also involved a fake open-source project hosted on GitHub. Hackers created a fake cryptocurrency trading bot, complete with fake updates, detailed documentation, and several user accounts to make the project seem active and trustworthy.

On September 1, SlowMist’s Yu Xian reported that attackers stole WLFI tokens from Ethereum wallets. How? Read the full story.


]]>
https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/feed/ 0 57122
Hackers breach Toptal GitHub account, publish malicious npm packages https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/ https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/#respond Thu, 24 Jul 2025 15:13:12 +0000 https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/

NPM

Hackers compromised Toptal’s GitHub organization account and used their access to publish ten malicious packages on the Node Package Manager (NPM) index.

The packages included data-stealing code that collected GitHub authentication tokens and then wiped the victims’ systems.

Toptal is a freelance talent marketplace that connects companies with software developers, designers, and finance experts. The company also maintains internal developer tools and design systems, most notably Picasso, which they make available through GitHub and NPM.

Attackers hijacked Toptal’s GitHub organization on July 20, and almost immediately made public all 73 of the repositories available, exposing private projects and source code.

Tweet

In the days that followed, the attackers modified the source code of Picasso on GitHub to include malware and published 10 malicious packages on NPM as Toptal, making them appear as legitimate updates.

The malicious packages and modified versions are:

  • @toptal/picasso-tailwind (v3.1.0)
  • @toptal/picasso-charts (v59.1.4)
  • @toptal/picasso-shared (v15.1.0)
  • @toptal/picasso-provider (v5.1.1)
  • @toptal/picasso-select (v4.2.2)
  • @toptal/picasso-quote (v2.1.7)
  • @toptal/picasso-forms (v73.3.2)
  • @xene/core (v0.4.1)
  • @toptal/picasso-utils (v3.2.0)
  • @toptal/picasso-typography (v4.1.4)

The malicious packages were downloaded roughly 5,000 times before being detected, likely infecting developers with malware.

The hackers injected the malicious code into ‘package.json’ files to add two functions: steal data (‘preinstall’ script) and wipe hosts (‘postinstall’ script).

The first extracts the victim’s CLI authentication token and sends it to an attacker-controlled webhook URL, granting them unauthorized access to the target’s GitHub account.

After exfiltrating the data, the second script attempts to delete the entire filesystem with ‘sudo rm -rf –no-preserve-root /’ on Linux systems, or recursively and silently delete files on Windows.

According to code security platform Socket, Toptal deprecated the malicious packages on July 23 and reverted to safe versions, but issued no public statement to alert users who had downloaded the malicious releases to the risks.

Although the initial compromise method remains unknown, Socket lists multiple possibilities ranging from insider threats to phishing attacks targeting Toptal developers.

BleepingComputer has contacted Toptal for a statement, but we are still waiting for their response.

If you have installed any of the malicious packages, you are advised to revert to a previous stable version as soon as possible.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/feed/ 0 49418
Supply chain attack hits Gluestack NPM packages with 960K weekly downloads https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/ https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/#respond Sun, 08 Jun 2025 03:54:04 +0000 https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/

NPM

A significant supply chain attack hit NPM after 16 popular Gluestack ‘react-native-aria’ packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT).

BleepingComputer determined that the compromise began on June 6 at 4:33 PM EST, when a new version of the react-native-aria/focus package was published to NPM. Since then, 16 of the 20 Gluestack react-native-aria packages have been compromised on NPM, with the threat actors publishing a new version as recently as two hours ago.

Ongoing compromise of NPM packages
Ongoing compromise of NPM packages
Source: BleepingComputer

The supply chain attack was discovered by cybersecurity firm Aikido Security, who discovered obfuscated code injected into the lib/index.js file for the following packages:

Package Name Version Weekly Downloads
react-native-aria/button 0.2.11 51,000
react-native-aria/checkbox 0.2.11 81,000
react-native-aria/combobox 0.2.10 51,000
react-native-aria/disclosure 0.2.9 3
react-native-aria/focus 0.2.10 100,000
react-native-aria/interactions 0.2.17 125,000
react-native-aria/listbox 0.2.10 51,000
react-native-aria/menu 0.2.16 22,000
react-native-aria/overlays 0.3.16 96,000
react-native-aria/radio 0.2.14 78,000
react-native-aria/switch 0.2.5 477
react-native-aria/toggle 0.2.12 81,000
react-native-aria/utils 0.2.13 120,000
gluestack-ui/utils 0.1.17 55,000
react-native-aria/separator 0.2.7 65
react-native-aria/slider 0.2.13 51,000

These packages are very popular, with approximately 960,000 weekly downloads, making this a supply chain attack that could have widespread consequences.

The malicious code is heavily obfuscated and is appended to the last line of source code in the file, padded with many spaces, so it’s not easily spotted when using the code viewer on the NPM site.

Malicious code added to end of index.js file
Malicious code added to end of index.js file
Source: BleepingComputer

Aikido told BleepingComputer that the malicious code is nearly identical to a remote access trojan in another NPM compromise they discovered last month.

The researcher’s analysis of the previous campaign explains that the remote access trojan will connect to the attackers’ command and control server and receive commands to execute.

These commands include:

  • cd – Change current working directory
  • ss_dir – Reset directory to script’s path
  • ss_fcd: – Force change directory to
  • ss_upf:f,d – Upload single file f to destination d
  • ss_upd:d,dest – Upload all files under directory d to destination dest
  • ss_stop – Sets a stop flag to interrupt current upload process
  • Any other input – Treated as a shell command, executed via child_process.exec()

The trojan also performs Windows PATH hijacking by prepending a fake Python path (%LOCALAPPDATA%\Programs\Python\Python3127) to the PATH environment variable, allowing the malware to silently override legitimate python or pip commands to execute malicious binaries.

Aikido sercurity researcher Charlie Eriksen has attempted to contact Gluestack about the compromise by creating GitHub issues on each of the project’s repositories, but there has not been any response at this time.

“No response from package maintainers (it’s morning on a saturday in the US which is prob exactly why its happening now),” Arkido told BleepingComputer.

“NPM we have contacted and reported each package, this is a process that usually takes multiple days for NPM to address though.”

Aikido also attributes this attack to the same threat actors who compromised four other NPM packages earlier this week named biatec-avm-gas-stationcputil-nodelfwfinance/sdk, and lfwfinance/sdk-dev.

BleepingComputer reached out to Gluestack about the compromised packages but has not received a reply at this time.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/feed/ 0 40780
North Korean Lazarus hackers infect hundreds via npm packages https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/ https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/#respond Wed, 12 Mar 2025 03:11:40 +0000 https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/

NPM

Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus.

The packages, which have been downloaded 330 times, are designed to steal account credentials, deploy backdoors on compromised systems, and extract sensitive cryptocurrency information.

The Socket Research Team discovered the campaign, which linked it to previously known Lazarus supply chain operations.

The threat group is known for pushing malicious packages into software registries like npm, which is used by millions of JavaScript developers, and compromising systems passively.

Similar campaigns attributed to the same threat actors have been spotted on GitHub and the Python Package Index (PyPI).

This tactic often allows them to gain initial access to valuable networks and conduct massive record-breaking attacks, like the recent $1.5 billion crypto heist from the Bybit exchange.

The six Lazarus packages discovered in npm all employ typosquatting tactics to trick developers into accidental installations:

  1. is-buffer-validator – Malicious package mimicking the popular is-buffer library to steal credentials.
  2. yoojae-validator – Fake validation library used to extract sensitive data from infected systems.
  3. event-handle-package – Disguised as an event-handling tool but deploys a backdoor for remote access.
  4. array-empty-validator – Fraudulent package designed to collect system and browser credentials.
  5. react-event-dependency – Poses as a React utility but executes malware to compromise developer environments.
  6. auth-validator – Mimics authentication validation tools to steal login credentials and API keys.

The packages contain malicious code designed to steal sensitive information, such as cryptocurrency wallets and browser data that contains stored passwords, cookies, and browsing history.

They also load the BeaverTail malware and the InvisibleFerret backdoor, which North Koreans previously deployed in fake job offers that led to the installation of malware.

Code snippet that downloads malware payloads
Code snippet that downloads malware payloads
Source: Socket

“The code is designed to collect system environment details, including the hostname, operating system, and system directories,” explains the Socket report.

“It systematically iterates through browser profiles to locate and extract sensitive files such as Login Data from Chrome, Brave, and Firefox, as well as keychain archives on macOS.”

“Notably, the malware also targets cryptocurrency wallets, specifically extracting id.json from Solana and exodus.wallet from Exodus.”

All six Lazarus packages are still available on npm and the GitHub repositories, so the threat is still active.

Software developers are advised to double-check the packages they use for their projects and constantly scrutinize code in open-source software to find suspicious signs like obfuscated code and calls to external servers.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/feed/ 0 24627