According to recent reports, a massive supply chain cybersecurity breach has affected the npm ecosystem, which is used to manage and distribute JavaScript packages. A highly reputable developer’s npm account has been compromised, allowing the attacker to contaminate widely used packages, such as Chalk, with malicious code that steals cryptocurrency.
Notably, these packages command over a billion downloads weekly as they’re essential to various forms of Web2 and Web3 software development and operations. Hence, this malicious code could spread widely into numerous applications without the developers’ immediate knowledge.
How the Malware Works
Based on a recent X post from Charles Guillemet, a CTO at Ledger, a secure crypto hardware wallet issuer, the malware has been designed for swift address poisoning or swapping.
🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
The malicious payload works…
— Charles Guillemet (@P3b7_) September 8, 2025
With the code installed on a potential victim’s computer, the attacker gains access to the user’s crypto addresses and transactions. The code also identifies a user’s crypto transactions and swiftly swaps the receiving address with the hacker’s own via some automated tools. Consequently, the victim unknowingly sends crypto to an attacker’s wallet address.
Notably, developers often install packages on npm without examining every line; thus, the hacker designed this malware as a single-line utility package that spans the dependency trees of many projects worldwide.
Take Action to Secure Your Funds
Notably, the best way to avoid the malware at the time is to abstain from processing any on-chain transactions until the malicious code is completely removed from the npm package and a malware-free update is pushed to the public for download.
This precaution applies to all crypto users, regardless of the blockchain network, as the malicious code contains a function called checkethereumw, designed to check if window.ethereum, an object injected by wallet browser extensions such as MetaMask or Phantom, exists in a potential victim’s browser.
Moreover, another function in the malicious code contains various crypto wallet addresses belonging to the attacker. This allows the bad actor to steal any asset from any network.
Although hardware wallet users are relatively safe, it is essential to thoroughly examine every transaction and address before signing to ensure maximum safety.
Some Crypto Platforms Claim Safety
Following the news, several crypto platforms, particularly those based on the Solana network, have claimed to be free from the malware. This includes Solana’s leading DEX aggregator Jupiter. The Solana-based platform assured users via an X post that transactions within its ecosystem are safe.
“We’ve confirmed across the source code that none of the affected package-versions exist in any Jupiter product.”
Staking platform Marinade Finance also revealed that its security team has thoroughly reviewed the project’s system and found no vulnerabilities. However, it also warns users to stay vigilant and take needed safety precautions as the situation unfolds gradually.
Other platforms, such as Drift Protocol, Solflare, and Kamino Finance, have also assured users of the safety of their funds. They added that they have “no dependency on the compromised packages.”












