Security Agency: NPM Supply Chain Attacked, Developer qix Affected
Sep 09, 2025 07:48:03
ChainCatcher message, according to market news, well-known developer qix has had npm packages injected with malicious code due to a phishing attack, with related packages including chalk, strip-ansi, color-convert, etc.
The attack method involves hooking wallet functions, tampering with ETH/SOL transaction receiving addresses, and replacing addresses in network responses. User advice: be sure to verify the recipient and amount in the wallet interface, check for address changes after pasting, review recent transactions, and prioritize using hardware wallets for high-value operations.
Latest News
ChainCatcher
Dec 26, 2025 11:45:19
ChainCatcher
Dec 26, 2025 11:41:01
ChainCatcher
Dec 26, 2025 11:30:29
ChainCatcher
Dec 26, 2025 11:15:26
ChainCatcher
Dec 26, 2025 11:14:42


