Massive npm Supply Chain Attack Hijacks 2.6 Billion Weekly Downloads via Phishing Compromise
Attackers compromised a key npm maintainer's account through sophisticated phishing, injecting malicious code into 19 popular packages with over 2.6 billion weekly downloads. The malware hijacks cryptocurrency transactions by rewriting wallet addresses in real-time. This represents one of the largest software supply chain attacks in history, impacting developers globally.