Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Hackers left empty handed after a large number of NPM supply-chain attack
    Security

    Hackers left empty handed after a large number of NPM supply-chain attack

    PineapplesUpdateBy PineapplesUpdateSeptember 11, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Hackers left empty handed after a large number of NPM supply-chain attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers left empty handed after a large number of NPM supply-chain attack

    The largest supply-series agreement in the history of NPM ecosystem has affected all the cloud environment, but the attacker made a little profit from it.

    The attack occurred earlier this week when Anuhar Josh Junn (QIX) fell for a password reset fishing greed and many of them compromised on highly popular NPM packages, among them Stalking And Degub-js, This is cumulatively more than 2.6 billion weekly downloads.

    After achieving access to the Junn’s account, the attackers pushed malicious updates with malicious modules, which the danger stole the actor to stole the Cryptocurrency by redressing the transaction.

    The open-source software community quickly discovered the attack, and all malicious packages were removed within two hours.

    According to the researchers at the Cloud Security Company Vis, one or more compromised package, which are fundamental construction blocks for almost any JavaScript/node project, was used in 99% of the cloud environment.

    During the two -hour window they were available for download, compromised packages were drawn by about 10% cloud environment.

    “During the low 2-hour time limit, the malicious versions were available on the NPM, the malicious code successfully reached 1 in the 10 cloud environment,” Explained Wiz.

    “It acts to demonstrate how fast the malicious code can be publicized in such supply chain attacks.”

    Picture
    Source: Wiz

    The 10% figure is based on the visibility of the customer cloud environment, as well as WIZ in public sources. Although it may not be a representative percentage, it is still a sign of rapid spread and access to attack.

    The attackers earned less than $ 1,000

    Although the attack caused remarkable disruption, companies require a significant number of hours for cleaning, reconstruction and auditing, safety implications are negligible, such as danger like the actor’s benefits.

    According to an analysis by Safety coalitionInjected codes The Cryptocurrency wallet address exchange with targeted browser environment, hooking atherium and solana signing request, attacker-invasive (crypto-jacking).

    The type of payload is one that saves companies that have pulled the compromised equipment from a very serious security event, as the danger actor may have used his reach for reverse shell, can later be transferred to the network, or planting destructive malware.

    Despite the massive and many victims of the attack, the attackers were able to divert only five cents ATH and an almost unknown memecoin of $ 20 value.

    Do

    Socket researchers published a report yesterday, alerting the same fishing campaign Also impressed duckdbAncharcate account, compromising the packages of the project with the same crypto-chori code.

    According to him, the benefits of the attackers discovered about $ 429, $ 429 in Atherium, $ 46 in Solana, and BTC, Tron, BCH and LTC have small amounts in small quantities.

    It is also noted that the attacker’s wallet addresses that keep in any important quantity have been flagged off, which limits their ability to convert or use small money they have made.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    Attack empty hackers handed large left NPM number supplychain
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleApple Watch Series 11 vs Samsung Galaxy Watch 8: I have tested both, and here is the winner
    Next Article Microsoft Tap anthropic for AI in Excel, signaling distance from Openai
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    How a simple link allowed hackers to bypass Copilot’s security guardrails – and what Microsoft did about it

    January 19, 2026
    Startups

    Your Bluetooth headphones may be under attack – here’s what to do next

    January 15, 2026
    Startups

    Forget the Samsung S25 Ultra: This Android alternative has battery life that left me speechless

    December 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.