Stand Up for Investors' Right to Know – Say No to Dumping Sell-Offs! [RootData Bounty Campaign]
API Download the RootData App

Security Agency: NPM Supply Chain Attacked, Developer qix Affected

Sep 09, 2025 07:48:03

Share to

ChainCatcher message, according to market news, well-known developer qix has had npm packages injected with malicious code due to a phishing attack, with related packages including chalk, strip-ansi, color-convert, etc.

The attack method involves hooking wallet functions, tampering with ETH/SOL transaction receiving addresses, and replacing addresses in network responses. User advice: be sure to verify the recipient and amount in the wallet interface, check for address changes after pasting, review recent transactions, and prioritize using hardware wallets for high-value operations.

Recent Fundraising

More
$1M Dec 25
$35M Dec 24
$2M Dec 24

New Tokens

More
Dec 23
Dec 20

Latest Updates on 𝕏

More