Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Compromised files replace npm packages with a combined 2 billion weekly downloads

A hacker wearing a hoodie sitting at a computer, his face hidden.
  • Over a dozen popular npm packages were compromised in a phishing-based supply chain attack
  • The malware targeted crypto users by hijacking wallet addresses during transactions
  • Some called it the most widespread npm compromise to date, affecting 2 billion weekly downloads

More than a dozen npm packages with two billion downloads a week were compromised in a supply chain attack that targeted cryptocurrency users.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.