At least 18 popular JavaScript code packages, which are collectively downloaded more than two billion times each week, were temporarily compromised with malware after a developer involved in maintaining the projects fell victim to phishing.
The attack appears to have been quickly contained and narrowly focused on crypto theft. However, experts warn that a similar attack with a more malicious payload could lead to a malware outbreak that is much harder to detect and contain.
See also: Hackers stole $27 million worth of crypto from BigONE

This phishing email tricked a developer into logging into a fake NPM website and providing a unique code for two-factor authentication. The phishers then used that developer's NPM account to add malicious code to at least 18 popular JavaScript code.
Akido beenadded to at least 18 widely used code libraries available in NPM (Node Package Manager), which acts as a central hub for JavaScript development and the latest updates to widely used JavaScript components.
JavaScript is a powerful programming language used by countless websites to create a more interactive user experience. Developers can reuse existing code packages from NPM that are specifically designed for tasks like entering data into a form.
If cybercriminals manage to obtain NPM credentials from developers, they can insert malicious code that allows attackers to control what users see in their browser when they visit a website that uses one of the affected code libraries.
See also: Malicious extension for Cursor AI IDE allowed crypto theft

According to Akido, the attackers introduced code that silently intercepts cryptocurrency activities in the browser, handles wallet interactions, and rewrites payment destinations so that funds and authorizations are redirected to accounts controlled by the attackers without any visible signs to the user.
Akido used the social network Bsky to notify the affected developer, Josh Junon, who quickly responded that he was aware that he had been phished. The phishing email that Junon was sent was part of a larger campaign that mimicked NPM and informed recipients that they needed to update their two-factor authentication (2FA) credentials. The phishing website mimicked the NPM login page and stole Junon’s credentials and 2FA token. Once connected, the phishers changed the email address registered for Junon’s NPM account, temporarily locking him out.
Akido notified the maintainer at Bluesky, who responded that he was aware of the breach and began cleaning up the breached packages.
Junon also issued an apology to HackerNews, telling the community, “Yes, I was a victim.” He described the incident as a targeted attack and expressed his embarrassment over the situation.
See also: Europe: Crypto companies must not mislead the public

Philippe Caturegli,chief hacking officerat security consultancy Seralys, noted that the attackers registered the fake website — npmjs[.]help — just two days before sending the phishing email. The fake website used services from dnsexit[.]com, a dynamic DNS company that offers free domain names that can be quickly directed to any IP address.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
