Stand Up for Investors' Right to Know – Say No to Dumping Sell-Offs! [RootData Bounty Campaign]
API Download the RootData App

Data: The attacker of the NPM developer account is currently suspected to have only profited about 20 dollars

Sep 09, 2025 10:17:47

Share to

ChainCatcher news, according to CertiK Alert monitoring, the NPM account of developer Qix has been phished, with attackers injecting malicious code into npm. According to Security Alliance, the attackers seem to have profited only about 0.05 dollars worth of ETH and 20 dollars worth of Meme coins.

Earlier reports indicated that Ledger's Chief Technology Officer Charles Guillemet stated, "A large-scale supply chain attack is currently underway: the NPM account of a well-known developer has been compromised. The affected package has been downloaded over 1 billion times, which means the entire JavaScript ecosystem may be at risk. The malicious code works by silently altering cryptocurrency addresses in the background to steal funds."

Recent Fundraising

More
$35M 12월 24
$2M 12월 24
$1M 12월 24

New Tokens

More
12월 23
12월 20
12월 19

Latest Updates on 𝕏

More
12월 23
12월 23
12월 23