A massive supply chain attack is targeting cryptocurrency users through compromised JavaScript packages with over 2.6 billion weekly downloads. Hackers injected malware that intercepts and redirects crypto transactions to attacker-controlled wallets. Security researchers warn this represents the largest infrastructure compromise in history affecting the entire JavaScript ecosystem.
- Attack compromised 18 JavaScript packages with 2.6+ billion weekly downloads including fundamental tools like chalk, debug, and ansi-styles
- Malware intercepts transactions across 6 major blockchain networks (Ethereum, Bitcoin, Solana, Tron, Litecoin, Bitcoin Cash) and replaces destination addresses
- Hardware wallet users protected if they verify transactions before signing, while software wallet users advised to avoid on-chain transactions