Security Agency: NPM Supply Chain Attacked, Developer qix Affected
Sep 09, 2025 07:48:03
ChainCatcher message, according to market news, well-known developer qix has had npm packages injected with malicious code due to a phishing attack, with related packages including chalk, strip-ansi, color-convert, etc.
The attack method involves hooking wallet functions, tampering with ETH/SOL transaction receiving addresses, and replacing addresses in network responses. User advice: be sure to verify the recipient and amount in the wallet interface, check for address changes after pasting, review recent transactions, and prioritize using hardware wallets for high-value operations.
Latest News
ChainCatcher
Dec 28, 2025 23:47:52
ChainCatcher
Dec 28, 2025 23:41:51
ChainCatcher
Dec 28, 2025 23:22:36
ChainCatcher
Dec 28, 2025 23:12:01
ChainCatcher
Dec 28, 2025 23:01:13


