September 9, 2025 • 5 min read
NPM Supply Chain Attack Targets BTC, ETH, SOL, LTC Wallets
Quick Answer
A massive software supply chain attack has slipped wallet-draining malware into 18 popular open-source code libraries used by millions of web apps. Losses so far are small, at just over $500 according to Arkham Intelligence.
Key Facts
| Attack type | NPM software supply chain compromise |
| Packages affected | 18 |
| Weekly downloads | Over 2.6 billion |
| Exposure window | About two hours |
| Chains targeted | BTC, ETH, LTC, SOL, TRX, BCH |
| Main technique | Clipboard hijacking and address swapping |
| Funds stolen | Over $500 (Arkham Intelligence) |
| Reported | September 8, 2025 |
- What happened: 18 popular software libraries on NPM (used by millions of apps) were secretly injected with malicious code.
- How it works: The malware swaps legitimate wallet addresses with attacker-controlled ones during transactions.
- How much is lost: Initially $50, rising to over $500 stolen at the time of writing, according to Arkham Intelligence.
- Security precautions: Verify full addresses, send test transactions, use hardware or air-gapped wallets.
What Actually Happened
If you’ve never heard of NPM, you’re not alone. It’s not a blockchain project, it’s a software “package manager” used by developers worldwide. Think of it as an app store for pieces of code. Every time you use a web app, chances are it relies on dozens (if not hundreds) of these packages in the background.
The attack struck when hackers compromised the account of a respected maintainer and published malicious updates to 18 widely used packages. Together, these libraries are downloaded over 2.6 billion times each week. That means the poisoned code spread instantly into countless apps and services, including those that handle cryptocurrency transactions.
Even though the infected versions were online for only about two hours, that was enough time for exposure to spread across the internet.
How the NPM Supply Chain Attack Works
The malicious code was tailored specifically to steal cryptocurrency. Here’s how it operated:
- Clipboard Hijacking: If you copied a crypto address to your clipboard (e.g., to send Bitcoin), the malware silently swapped it with the attacker’s address. Because many users only check the first and last few characters, this trick works frighteningly well.
- Address Spoofing with Lookalikes: Instead of inserting a completely different string, the attacker generated addresses that looked similar to the victim's legitimate addresses. This made the theft harder to notice until it was too late.
- Transaction Interception: For blockchains like Ethereum and Solana, the malware hooked into wallet APIs and monitored transaction requests and replaced the destination address with the attacker’s before you signed it.
🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
The malicious payload works…
— Charles Guillemet (@P3b7_) September 8, 2025
Which Blockchains Were Targeted
The attackers went multi-chain from the start, coding their malware to recognize different address formats and transaction flows. The following blockchains were confirmed targets:
Tracking the Attacker: Arkham Intelligence

Blockchain analysis platform Arkham Intelligence has already flagged the attacker as an entity in its system. The wallets linked to the hack were being tracked in real time.
- Initially, only $50 worth of crypto had been siphoned.
- At the time of writing, that number had risen to over $500.
- The dedicated Arkham entity view shows exactly which wallets are receiving stolen funds.
Security Recommendations for Crypto Holders
1. Always Verify Transactions
- Don’t trust just the first and last few characters, read the full address.
- Send a small test transaction before moving large amounts.
- Be aware that malware can replace clipboard contents, don’t assume what you copied is what you’ll paste.
2. Use Hardware Wallets (with Screens)
Ledger’s CTO reminded the community: “What You See Is What You Sign.”
- A hardware wallet shows you transaction details on its own secure screen.
- You must physically confirm before signing, making it nearly impossible for malware to alter the recipient behind the scenes.
3. Wallet Etiquette
- Store Bitcoin on a dedicated Bitcoin-only device. Don’t mix it with every altcoin wallet you have.
- Avoid blind signing smart contracts. Always check what permissions you’re granting.
- Don’t reuse Bitcoin addresses. It improves privacy and reduces potential risks tied to future quantum computing.
4. Consider Air-Gapped Wallets
An air-gapped wallet (offline device) assumes your PC or mobile phone is already compromised. These devices never connect directly to the internet, reducing exposure to malware.
5. Stay Informed About Other Attack Types
Clipboard hijacking is only one method. Others include:
- UI Spoofing: Where the interface shows you the “correct” address, but the signed transaction points elsewhere.
- Approval Draining: On Ethereum and similar chains, attackers trick you into granting unlimited spending rights.
Wallets Safe from This Attack
Confirmed unaffected NPM attack:@covewallet @nunchuk_io @AquaBitcoin @Blockstream @SparrowWallet @wasabiwallet @COLDCARDwallet @SpecterWallet @ElectrumWallet @FOUNDATIONdvcs @selfcustodykrux @SeedSigner @bitcoinKeeper_
Will add others below in the thread as I'm informed of…— BTC Sessions 😎 (@BTCsessions) September 9, 2025
Educator @BTCSessions compiled a list of hardware and software wallets unaffected by this specific NPM attack. If you’re worried, cross-check your wallet against that list before sending funds.
Bigger Lessons From the Attack
The reality is that your computer, browser, and phone can always be compromised. The attacker doesn’t need to break Bitcoin, they just need to trick you into sending it to the wrong place.
This is why air-gapped and hardware wallets exist: they operate on the assumption that your regular device is already infected. By shifting the signing process onto a secure, isolated device, you regain control.
Time to Get a Hardware Wallet
This NPM supply chain attack is a clear signal: the days of storing serious crypto on hot wallets or browser extensions should be over.
If you hold meaningful amounts of Bitcoin or other crypto:
- Always verify addresses manually.
- Do test transactions before sending large sums.
- Get a hardware wallet, Ledger, Trezor, Coldcard, Passport, Keystone or similar.
- Or even build your own using open-source projects like Specter DIY or Seedsigner.
The cost or effort of proper wallet security is nothing compared to the risk of losing your funds forever.
The lesson is simple: if you value your Bitcoin, treat your wallet setup like it’s already under attack, because after this NPM hack, that’s closer to the truth than ever.
Brought to You by Flush, the Ultimate Crypto Casino Destination for Gaming Enthusiasts
At Flush, a leading Crypto casino, you can enjoy a smooth, secure gaming experience with real money online slots, live casino games like poker, blackjack, baccarat, roulette, and much more. As a premier crypto casino, Flush features top titles from providers like Nolimit City, Hacksaw Gaming, Pragmatic Play and many more, ensuring an exciting lineup of games for every player.
New players at Flush get a welcome bonus of up to 150% to extend their first session, plus automatic entry into the Weekly Races prize pool when they spin slots.
If you want to play crypto slots with real money, Flush is built for it. Our lobby spans 6,000+ games from 70+ providers, the welcome offer is a welcome bonus of up to 150%, and USDT TRC-20 withdrawals typically clear in under 2 minutes for standard play.
How We Researched This
Methodology
This report summarizes public disclosures about the September 2025 NPM compromise, including the original write-up of the malicious code, security analyses from Aikido and SiliconANGLE, posts by Ledger's CTO Charles Guillemet, and a list of unaffected wallets compiled by BTC Sessions. Figures on stolen funds come from Arkham Intelligence's entity tracking and were changing as the story developed. Security recommendations reflect widely accepted self-custody practices and are general guidance, not a guarantee against every attack.
FAQ
Frequently Asked Questions
What happened in the NPM supply chain attack?
How does the NPM crypto malware steal funds?
Which blockchains were targeted?
How much crypto was stolen?
How can I protect my crypto from this kind of attack?
Which wallets were unaffected by the NPM attack?
Share This Post
Share this post for your chance to win!
Related Posts
Level up your knowledge

American Bitcoin (ABTC) Explained: What the Company Is
American Bitcoin (ABTC) is a Nasdaq listed Bitcoin mining and treasury company tied to Hut 8 and the Trump family. Here's what the company actually does, stated as fact, not opinion.
5 min read

Japan Reclassifies Crypto as Financial Asset 2026
Japan's parliament reclassified crypto as a financial asset and cut its top crypto tax rate from 55% to 20%, effective 2028. Here is what it signals globally.
5 min read

Alberta Opens Regulated iGaming 2026: What It Signals
Alberta's regulated iGaming market launched July 13, 2026 with 22 operators live, several running crypto and stablecoin deposit rails on layer two networks.
5 min read