GM Locksmiths,
Some of you might have heard that a major NPM attack took place yesterday. NPM stands for Node Package Manager and is the default package manager for the JavaScript runtime environment Node.js. NPM allows developers to install, share, and manage open-source code libraries (or packages) efficiently for JavaScript projects.
On September 8, 2025, an attacker gained access to the accounts of a trusted maintainer and published malicious updates to 18 popular NPM packages, including chalk and debug, which injected harmful code targeting browser-based crypto wallets. The attack spread rapidly to millions of downstream apps until the community responded and removed the compromised versions within hours.
Users are affected if they installed or ran projects that pulled the infected NPM packages during the window when malicious versions were live, primarily impacting browser-based crypto wallets and blockchain interactions. The risk is limited to those who updated or deployed projects between September 8 and the official package rollbacks, and anyone exposed should immediately update dependencies and review wallet security.
That said 𝒊𝒕 𝒅𝒐𝒆𝒔𝒏'𝒕 𝒂𝒇𝒇𝒆𝒄𝒕 𝑼𝒏𝒍𝒐𝒄𝒌 𝑷𝒓𝒐𝒕𝒐𝒄𝒐𝒍 𝒅𝒊𝒓𝒆𝒄𝒕𝒍𝒚 𝒊𝒏 𝒂𝒏𝒚 𝒘𝒂𝒚, yet 𝘄𝗲 𝗿𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱 𝗸𝗲𝗲𝗽𝗶𝗻𝗴 𝘁𝗿𝗮𝗻𝘀𝗮𝗰𝘁𝗶𝗼𝗻𝘀 𝘁𝗼 𝗮 𝗺𝗶𝗻𝗶𝗺𝘂𝗺 𝘂𝗻𝘁𝗶𝗹 𝘁𝗵𝗲 𝗼𝘃𝗲𝗿𝗮𝗹𝗹 𝗲𝗰𝗼𝘀𝘆𝘀𝘁𝗲𝗺 𝗿𝗶𝘀𝗸 𝗵𝗮𝘀 𝗲𝘃𝗮𝗽𝗼𝗿𝗮𝘁𝗲𝗱.
Stay SAFU ✊💜