NEW: Unlock the Future of Finance with CRYPTO ENDEVR - Explore, Invest, and Prosper in Crypto!
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
No Result
View All Result

Crypto Users Warned to Stop Transacting as Massive Exploit Threatens Apps and Wallets

Crypto Users Warned to Stop Transacting as Massive Exploit Threatens Apps and Wallets
Share on FacebookShare on Twitter

rewrite this content

Swathes of crypto users could be at risk of having their funds stolen following the discovery of compromised JavaScript code packages, Ledger CTO Charles Guillemet warned Monday.

NPM is a prominent package manager for JavaScript, and Guillemet said on X that the entire programming language’s ecosystem could be vulnerable after a reputable developer’s account was compromised, potentially spreading a malicious payload to various websites.

“The malicious payload works by silently swapping crypto addresses on the fly to steal funds,” he said, adding that compromised packages have been downloaded more than 1 billion times. Guillemet added that funds on “potentially all chains” could be vulnerable to the exploit.

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.

The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

“I would strongly recommend not signing any crypto transactions right now,” software developer Cygaar meanwhile warned, noting that “various crypto websites” could be vulnerable.

Blockchain security firm Blockaid said on X that the compromise impacts around two dozen popular packages, such as “color-name” and “color-string.” NPM hosts packages of reusable code that users can integrate into their projects, which are written by others.

“It changes the destination address of transactions and approvals to be the attacker’s addresses rather than the address you’re actually trying to interact with,” Cygaar explained.

NPM later appeared to disable the compromised packages, Cygaar added. However, he encouraged developers to still check their dependencies, noting that they could’ve downloaded a compromised package before the change was made.

The sentiment was echoed by the author of a post that Guillemet linked to on X, which stated that they are “actively working with the NPM security team to resolve the issue” and that the malicious code had been removed from most of the affected webpages.

The author said that the NPM account impacted was called “qix,” and the malicious patch impacted “some of the most fundamental utilities in JavaScript” that are used as building blocks for countless projects.

Editor’s note: This story is breaking and will be updated with additional context.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

in well organized HTML format with all tags properly closed. Create appropriate headings and subheadings to organize the content. Ensure the rewritten content is approximately 1500 words. Do not include the title and images. please do not add any introductory text in start and any Note in the end explaining about what you have done or how you done it .i am directly publishing the output as article so please only give me rewritten content. At the end of the content, include a “Conclusion” section and a well-formatted “FAQs” section.

cryptoendevr

cryptoendevr

Related Stories

US Lawmakers Seek Treasury Report on Feasibility, Security of Government-Held Bitcoin

US Lawmakers Seek Treasury Report on Feasibility, Security of Government-Held Bitcoin

September 8, 2025
0

rewrite this content In brief If passed, Treasury would have 90 days to report on feasibility, legal authority, custody, and...

Strategy Buys 7 Million More In Bitcoin After S&P 500 Snub

Strategy Buys $217 Million More In Bitcoin After S&P 500 Snub

September 8, 2025
0

rewrite this content In brief Strategy has purchased 1,955 BTC for $217.4 million at $111,196 per coin, following Friday's S&P...

Metaplanet Acquires 136 More Bitcoin as It Races Toward 2026 Target

Metaplanet Acquires 136 More Bitcoin as It Races Toward 2026 Target

September 8, 2025
0

rewrite this content In brief Metaplanet has bought another 136 BTC for $15.2 million, bringing total holdings to 20,136 BTC....

AI Is on the Verge of Its Biggest Upgrade Yet: Emotional Intelligence

AI Is on the Verge of Its Biggest Upgrade Yet: Emotional Intelligence

September 7, 2025
0

rewrite this content In brief Two new research papers show how AI agents can be engineered with fixed psychological archetypes...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

🔴 Jake Brukhman’s 5K Bitcoin Bet?!

🔴 Jake Brukhman’s $475K Bitcoin Bet?!

September 7, 2025
Tether CEO refutes claims that the firm sold Bitcoin and bought gold

Tether CEO refutes claims that the firm sold Bitcoin and bought gold

September 7, 2025
AI Is on the Verge of Its Biggest Upgrade Yet: Emotional Intelligence

AI Is on the Verge of Its Biggest Upgrade Yet: Emotional Intelligence

September 7, 2025
Bitcoin, Ethereum, And Dogecoin Dominate Social Buzz

Bitcoin, Ethereum, And Dogecoin Dominate Social Buzz

September 7, 2025
Final Phase Of Crypto Pullback Incoming! (ALTCOIN ZONES!)

Final Phase Of Crypto Pullback Incoming! (ALTCOIN ZONES!)

September 7, 2025

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

CRYPTO ENDEVR

About Us

Crypto Endevr aims to simplify the vast world of cryptocurrencies and blockchain technology for our readers by curating the most relevant and insightful articles from around the web. Whether you’re a seasoned investor or new to the crypto scene, our mission is to deliver a streamlined feed of news and analysis that keeps you informed and ahead of the curve.

Links

Home
Privacy Policy
Terms and Services

Resources

Glossary

Other

About Us
Contact Us

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

© Copyright 2024. All Right Reserved By Crypto Endevr.

No Result
View All Result
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms

Copyright © 2024. All Right Reserved By Crypto Endevr