NPM Nightmare: Blockchain Developers Beware of Hijacked Packages!
Blockchain developers trying to build the future might want to watch their backs! Sonatype reports multiple NPM packages have been hijacked to deliver malware. These packages, with a total of 500,000 downloads, now include sneaky scripts capable of stealing sensitive data. Looks like even the blockchain needs a security chainmail these days!

Hot Take:
Looks like someone’s been playing a little game of hide and seek with blockchain developers. If you thought malware was scary, wait until it’s wearing a very convincing developer hat. This latest NPM package hijacking is a stark reminder that even the most secure-seeming systems can hide some nasty surprises. It’s like finding out your cat is actually a dog—a very sneaky, code-stealing dog.
Key Points:
- NPM packages used for blockchain apps have been hijacked to deliver malware.
- Malicious updates contain obfuscated scripts that steal sensitive information.
- Packages like ‘bnb-javascript-sdk-nobroadcast’ and ‘country-currency-map’ are affected.
- Hijacking likely due to compromised maintainer accounts via credential stuffing.
- Sonatype identified the issue, but GitHub repositories remain unaffected.
Already a member? Log in here