Igor Popov
Igor Popov

Crypto Wallets & Blockchain News Writer

September 9, 2025 • 5 min read

NPM Supply Chain Attack Targets BTC, ETH, SOL, LTC Wallets

NPM Supply Chain Attack Targets BTC, ETH, SOL, LTC Wallets

Updated: September 26, 2026

Quick Answer

A massive software supply chain attack has slipped wallet-draining malware into 18 popular open-source code libraries used by millions of web apps. Losses so far are small, at just over $500 according to Arkham Intelligence.

Key Facts

Attack typeNPM software supply chain compromise
Packages affected18
Weekly downloadsOver 2.6 billion
Exposure windowAbout two hours
Chains targetedBTC, ETH, LTC, SOL, TRX, BCH
Main techniqueClipboard hijacking and address swapping
Funds stolenOver $500 (Arkham Intelligence)
ReportedSeptember 8, 2025
  • What happened: 18 popular software libraries on NPM (used by millions of apps) were secretly injected with malicious code.
  • How it works: The malware swaps legitimate wallet addresses with attacker-controlled ones during transactions.
  • How much is lost: Initially $50, rising to over $500 stolen at the time of writing, according to Arkham Intelligence.
  • Security precautions: Verify full addresses, send test transactions, use hardware or air-gapped wallets.

What Actually Happened

If you’ve never heard of NPM, you’re not alone. It’s not a blockchain project, it’s a software “package manager” used by developers worldwide. Think of it as an app store for pieces of code. Every time you use a web app, chances are it relies on dozens (if not hundreds) of these packages in the background.

The attack struck when hackers compromised the account of a respected maintainer and published malicious updates to 18 widely used packages. Together, these libraries are downloaded over 2.6 billion times each week. That means the poisoned code spread instantly into countless apps and services, including those that handle cryptocurrency transactions.

Even though the infected versions were online for only about two hours, that was enough time for exposure to spread across the internet.

How the NPM Supply Chain Attack Works

The malicious code was tailored specifically to steal cryptocurrency. Here’s how it operated:

  • Clipboard Hijacking: If you copied a crypto address to your clipboard (e.g., to send Bitcoin), the malware silently swapped it with the attacker’s address. Because many users only check the first and last few characters, this trick works frighteningly well.
  • Address Spoofing with Lookalikes: Instead of inserting a completely different string, the attacker generated addresses that looked similar to the victim's legitimate addresses. This made the theft harder to notice until it was too late.
  • Transaction Interception: For blockchains like Ethereum and Solana, the malware hooked into wallet APIs and monitored transaction requests and replaced the destination address with the attacker’s before you signed it.

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.

The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

Which Blockchains Were Targeted

The attackers went multi-chain from the start, coding their malware to recognize different address formats and transaction flows. The following blockchains were confirmed targets:

Tracking the Attacker: Arkham Intelligence

Arkham Intelligence tracking wallets tied to NPM supply chain attack and crypto exposure - Flush

Blockchain analysis platform Arkham Intelligence has already flagged the attacker as an entity in its system. The wallets linked to the hack were being tracked in real time.

  • Initially, only $50 worth of crypto had been siphoned.
  • At the time of writing, that number had risen to over $500.
  • The dedicated Arkham entity view shows exactly which wallets are receiving stolen funds.

Security Recommendations for Crypto Holders

1. Always Verify Transactions

  • Don’t trust just the first and last few characters, read the full address.
  • Send a small test transaction before moving large amounts.
  • Be aware that malware can replace clipboard contents, don’t assume what you copied is what you’ll paste.

2. Use Hardware Wallets (with Screens)

Ledger’s CTO reminded the community: “What You See Is What You Sign.”

  • A hardware wallet shows you transaction details on its own secure screen.
  • You must physically confirm before signing, making it nearly impossible for malware to alter the recipient behind the scenes.

3. Wallet Etiquette

  • Store Bitcoin on a dedicated Bitcoin-only device. Don’t mix it with every altcoin wallet you have.
  • Avoid blind signing smart contracts. Always check what permissions you’re granting.
  • Don’t reuse Bitcoin addresses. It improves privacy and reduces potential risks tied to future quantum computing.

4. Consider Air-Gapped Wallets

An air-gapped wallet (offline device) assumes your PC or mobile phone is already compromised. These devices never connect directly to the internet, reducing exposure to malware.

5. Stay Informed About Other Attack Types

Clipboard hijacking is only one method. Others include:

  • UI Spoofing: Where the interface shows you the “correct” address, but the signed transaction points elsewhere.
  • Approval Draining: On Ethereum and similar chains, attackers trick you into granting unlimited spending rights.

Wallets Safe from This Attack

Confirmed unaffected NPM attack:@covewallet @nunchuk_io @AquaBitcoin @Blockstream @SparrowWallet @wasabiwallet @COLDCARDwallet @SpecterWallet @ElectrumWallet @FOUNDATIONdvcs @selfcustodykrux @SeedSigner @bitcoinKeeper_
Will add others below in the thread as I'm informed of…

— BTC Sessions 😎 (@BTCsessions) September 9, 2025

Educator @BTCSessions compiled a list of hardware and software wallets unaffected by this specific NPM attack. If you’re worried, cross-check your wallet against that list before sending funds.

Bigger Lessons From the Attack

The reality is that your computer, browser, and phone can always be compromised. The attacker doesn’t need to break Bitcoin, they just need to trick you into sending it to the wrong place.

This is why air-gapped and hardware wallets exist: they operate on the assumption that your regular device is already infected. By shifting the signing process onto a secure, isolated device, you regain control.

Time to Get a Hardware Wallet

This NPM supply chain attack is a clear signal: the days of storing serious crypto on hot wallets or browser extensions should be over.

If you hold meaningful amounts of Bitcoin or other crypto:

The cost or effort of proper wallet security is nothing compared to the risk of losing your funds forever.

The lesson is simple: if you value your Bitcoin, treat your wallet setup like it’s already under attack, because after this NPM hack, that’s closer to the truth than ever.

Brought to You by Flush, the Ultimate Crypto Casino Destination for Gaming Enthusiasts

At Flush, a leading Crypto casino, you can enjoy a smooth, secure gaming experience with real money online slots, live casino games like poker, blackjack, baccarat, roulette, and much more. As a premier crypto casino, Flush features top titles from providers like Nolimit City, Hacksaw Gaming, Pragmatic Play and many more, ensuring an exciting lineup of games for every player.

New players at Flush get a welcome bonus of up to 150% to extend their first session, plus automatic entry into the Weekly Races prize pool when they spin slots.

If you want to play crypto slots with real money, Flush is built for it. Our lobby spans 6,000+ games from 70+ providers, the welcome offer is a welcome bonus of up to 150%, and USDT TRC-20 withdrawals typically clear in under 2 minutes for standard play.

How We Researched This

Methodology

This report summarizes public disclosures about the September 2025 NPM compromise, including the original write-up of the malicious code, security analyses from Aikido and SiliconANGLE, posts by Ledger's CTO Charles Guillemet, and a list of unaffected wallets compiled by BTC Sessions. Figures on stolen funds come from Arkham Intelligence's entity tracking and were changing as the story developed. Security recommendations reflect widely accepted self-custody practices and are general guidance, not a guarantee against every attack.

FAQ

Frequently Asked Questions

What happened in the NPM supply chain attack?
Hackers compromised the account of a respected NPM maintainer and published malicious updates to 18 widely used packages that together are downloaded over 2.6 billion times each week. The infected versions were online for about two hours.
How does the NPM crypto malware steal funds?
It hijacks the clipboard to swap copied crypto addresses, generates lookalike addresses that resemble the victim's own, and on chains like Ethereum and Solana hooks into wallet APIs to replace the destination address before you sign.
Which blockchains were targeted?
Confirmed targets were Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Solana (SOL), TRON (TRX) and Bitcoin Cash (BCH).
How much crypto was stolen?
According to Arkham Intelligence, the attacker initially siphoned about $50 worth of crypto, a figure that later rose to over $500.
How can I protect my crypto from this kind of attack?
Read the full address before sending, make a small test transaction first, and use a hardware or air-gapped wallet that shows transaction details on its own screen so you confirm exactly what you sign.
Which wallets were unaffected by the NPM attack?
BTC Sessions compiled a list of unaffected wallets, including Blockstream, Sparrow, Wasabi, Coldcard, Specter, Electrum, Foundation, Krux, SeedSigner, Nunchuk, Aqua, Cove and Bitcoin Keeper.
Igor Popov

Share This Post

Share this post for your chance to win!

Play at Flush.com

Crypto deposits, instant payouts.

PLAY NOW