The post Axios supply chain attack raises risk to crypto wallets appeared on BitcoinEthereumNews.com. Axios, one of the most popular JavaScript libraries, may beThe post Axios supply chain attack raises risk to crypto wallets appeared on BitcoinEthereumNews.com. Axios, one of the most popular JavaScript libraries, may be

Axios supply chain attack raises risk to crypto wallets

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Axios, one of the most popular JavaScript libraries, may be compromised and involved in a crypto wallet attack. The npm package attack is becoming more common, directly attacking projects, developers, and end users. 

An Axios npm package was published to the official JavaScript library, and unpublished just hours later. On-chain security experts intercepted the attack, which was active for around three hours. 

The npm packages were compromised through the credentials of @jasonsaayman, as researchers still looked for signs that the account was compromised. The affected packages were identified as [email protected] and [email protected].

As Cryptopolitan reported earlier, npm attacks often target crypto wallets and are especially risky for decentralized projects with large team holdings. 

What happened in the Axios npm attack? 

StepSecurity was among the first to identify the issue. Two malicious versions of the Axios HTTP client library were published through the compromised credentials of a lead Axios maintainer, bypassing the normal publishing pipeline on GitHub. 

According to StepSecurity, this was the most sophisticated attack against a widely used top-10 npm package. The malicious package version injects a new dependency, [email protected], which is not imported in the axios source code. The dependency runs a post-install script, active on all operating systems. 

After using the npm, the client is infected with a remote access trojan dropper, which has a live server and delivers the payloads. The malware also deletes itself and replaces the suspect .json with a clean version to evade detection. 

Which types of projects were affected?

The npm packages were among the most popular, with up to 100M weekly downloads. However, at this point, there are no reports of unauthorized crypto movement. Previously, an npm attack led to only $1,000 of crypto losses from obscure tokens. 

The only way to limit malicious npm is to track versions and not allow automated upgrades, or check new versions for potential malicious uploads. 

Researchers also discovered two additional malicious packages delivering payloads the same way – @shadanai/openclaw and @qqbrowser/openclaw-qbot. The attack follows the LiteLLM malicious code injection by just a week. 

There is no report of Web3 or OpenClaw projects being affected or any crypto stolen, for the duration of the attack. However, warnings were issued that npm attacks may now become the norm, either through stolen credentials or unauthorized publishers. The threat follows previous warnings on malicious code using the OpenClaw skill platform

The packages are not limited to Web3 or bot projects, and may affect any payloads linked to crypto wallets. The loss of trust in npm and pip installs for Python may also erode the general trust in the library ecosystem, with calls for a more secure upload path. 

The usage of AI agents may also lead to indiscriminate package downloading, spreading the threat. The actual effects on crypto wallets may not be immediate, but they still potentially expose wallet data. 

Your bank is using your money. You’re getting the scraps. Watch our free video on becoming your own bank

Source: https://www.cryptopolitan.com/supply-chain-attack-axios-crypto-wallets/

Market Opportunity
4 Logo
4 Price(4)
$0.013406
$0.013406$0.013406
-12.33%
USD
4 (4) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Brent Crude Forecast: Societe Generale Issues Stark $150 Risk Warning Amid Market Turbulence

Brent Crude Forecast: Societe Generale Issues Stark $150 Risk Warning Amid Market Turbulence

BitcoinWorld Brent Crude Forecast: Societe Generale Issues Stark $150 Risk Warning Amid Market Turbulence Global energy markets face renewed volatility as Societe
Share
bitcoinworld2026/03/31 16:50
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27
Best Crypto to Buy Today 17 September – XRP, Pi Coin, Solana

Best Crypto to Buy Today 17 September – XRP, Pi Coin, Solana

Scouting for the best crypto to buy today is no easy task. The sprawling digital asset market has hovered near the $4 trillion mark for a while, even though Bitcoin hit a fresh all-time high (ATH) of $124,128 just last month. The enthusiasm isn’t limited to Bitcoin either. Significant capital continues to pour into leading […] The post Best Crypto to Buy Today 17 September – XRP, Pi Coin, Solana appeared first on Cryptonews.
Share
Coinstats2025/09/18 06:36