• About
  • FAQ
  • Landing Page
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Crypto News
No Result
View All Result
Home Market

Slow Fog warns devs over malicious axios malware campaign

admin by admin
March 31, 2026
in Market
0
RedStone deploys price oracle to bolster Stellar DeFi security
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Slow Fog warns devs over malicious axios malware campaign插图

Slow Fog flags malicious axios releases pulling in plain-crypto-js malware, exposing crypto developers to cross-platform RATs and stolen credentials via npm.

Blockchain security firm Slow Fog has issued an urgent security reminder after newly published [email protected] and [email protected] releases pulled in a malicious dependency, [email protected], turning one of JavaScript’s most widely used HTTP clients into a supply chain weapon against crypto developers. Axios sees more than 80 million weekly downloads on npm, meaning even a short-lived compromise can ripple across wallet backends, trading bots, exchanges and DeFi infrastructure built on Node.js. In its advisory, Slow Fog warned that “users who installed [email protected] via npm install -g are potentially exposed,” recommending immediate credential rotation and thorough host-side investigation for signs of compromise.

The attack hinges on a fake cryptography package, [email protected], which is silently added as a new dependency and used solely to execute an obfuscated postinstall script that drops a cross-platform remote access trojan targeting Windows, macOS and Linux systems.

Security firm StepSecurity explained that “neither malicious version contains a single line of malicious code inside Axios itself,” and that instead “both inject a fake dependency, [email protected], whose only purpose is to run a postinstall script that deploys a cross-platform remote access trojan (RAT).” Socket’s research team noted that the malicious plain-crypto-js package was published just minutes before the compromised axios release, calling it a “coordinated supply chain attack” against the JavaScript ecosystem.

According to StepSecurity, the malicious axios releases were pushed using stolen npm credentials belonging to primary maintainer “jasonsaayman,” allowing attackers to bypass the project’s usual GitHub-based release flow. “It’s a live supply chain compromise in [email protected], which newly depends on [email protected]—a package published hours earlier and identified as obfuscated malware that executes shell commands and erases traces,” security engineer Julian Harris wrote on LinkedIn. npm has now removed the malicious versions and reverted the axios resolution back to 1.14.0, but any environment that pulled 1.14.1 or 0.3.4 during the attack window remains at risk until secrets are rotated and systems are rebuilt.

The compromise echoes earlier npm incidents that directly targeted crypto users, including a 2025 campaign in which 18 popular packages like chalk and debug silently swapped wallet addresses to steal funds, prompting Ledger CTO Charles Guillemet to warn that “the affected packages have already been downloaded over 1 billion times.” Researchers have also documented npm malware stealing keys from Ethereum, XRP and Solana wallets, and SlowMist has estimated that crypto hacks and frauds — including backdoored packages and AI-assisted supply chain attacks — caused more than $2.3 billion in losses in the first half of 2025 alone. For now, Slow Fog’s advice is blunt: downgrade axios to 1.14.0, audit dependencies for any trace of [email protected] or openclaw, and assume that any credentials touched by those environments are compromised.

In a previous crypto.news story on JavaScript supply chain attacks, Ledger’s Guillemet warned that compromised npm packages with more than 2 billion weekly downloads posed a systemic risk to dApps and wallets built on Node.js. Another story detailed how North Korea’s Lazarus Group planted malicious npm packages to backdoor developer environments and target Solana and Exodus wallet users. A third crypto.news story on next-generation malware showed how backdoor supply chain attacks via npm and low-cost AI tools helped criminals remotely control over 4,200 developer machines and contributed to billions of dollars in crypto losses.

News,Cryptocurrency,DeFi,Exchange#Slow #Fog #warns #devs #malicious #axios #malware #campaign1774969096

Related articles

Japan crypto leverage: Why is Japan considering higher crypto leverage limits? - 1

Japan crypto leverage: Why is Japan considering higher crypto leverage limits?

July 27, 2026
Garden Finance takes app offline after independent solver database compromise - 1

Garden Finance takes app offline after independent solver database compromise

July 27, 2026
Tags: axioscampaigndevsFogmaliciousmalwareSlowWarns
Share76Tweet47

Related Posts

Japan crypto leverage: Why is Japan considering higher crypto leverage limits? - 1

Japan crypto leverage: Why is Japan considering higher crypto leverage limits?

by admin
July 27, 2026
0

Japan has moved closer to easing its cryptocurrency leverage trading rules after a senior ruling party lawmaker said the current...

Garden Finance takes app offline after independent solver database compromise - 1

Garden Finance takes app offline after independent solver database compromise

by admin
July 27, 2026
0

Garden Finance has temporarily taken its application offline after an attacker compromised the off-chain database of an independent solver, leading...

Brian Armstrong’s NewLimit Raises $435M for Human Trials

Brian Armstrong says AI agents will out-transact humans using crypto

by admin
July 27, 2026
0

Coinbase chief executive Brian Armstrong said artificial intelligence and crypto are not rival trends. Summary Armstrong expects autonomous AI agents...

Sberbank sets Dec. 1 deadline for Russia crypto trading launch

Sberbank sets Dec. 1 deadline for Russia crypto trading launch

by admin
July 26, 2026
0

Sberbank plans to launch cryptocurrency trading infrastructure and a digital depository by Dec. 1, 2026. Summary Sberbank plans to launch...

Upbit lists Derive (DRV) with KRW, BTC and USDT trading pairs

Upbit expands KRW market with two major DeFi token listings

by admin
July 26, 2026
0

Upbit has added Morpho (MORPHO) and Euler (EUL) to its Korean won market, expanding direct KRW trading for two Ethereum-based...

Load More
  • Trending
  • Comments
  • Latest
Rain raises $250m series C to expand stablecoin payments infrastructure - 1

Rain raises $250m series C to expand stablecoin payments infrastructure

January 10, 2026
US Commodities Regulator Beefs Up Bitcoin Futures Review缩略图

US Commodities Regulator Beefs Up Bitcoin Futures Review

January 16, 2023
What is the Difference Between Public and Permissioned Blockchains?缩略图

What is the Difference Between Public and Permissioned Blockchains?

December 28, 2022
Elon Musk Offers to Buy 100% of Twitter, Calls it ‘Best and Final Offer’

Elon Musk Offers to Buy 100% of Twitter, Calls it ‘Best and Final Offer’

March 4, 2023
US Commodities Regulator Beefs Up Bitcoin Futures Review缩略图

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability缩略图

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech缩略图

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55缩略图

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Japan crypto leverage: Why is Japan considering higher crypto leverage limits? - 1

Japan crypto leverage: Why is Japan considering higher crypto leverage limits?

July 27, 2026
Garden Finance takes app offline after independent solver database compromise - 1

Garden Finance takes app offline after independent solver database compromise

July 27, 2026
Brian Armstrong’s NewLimit Raises $435M for Human Trials

Brian Armstrong says AI agents will out-transact humans using crypto

July 27, 2026
Sberbank sets Dec. 1 deadline for Russia crypto trading launch

Sberbank sets Dec. 1 deadline for Russia crypto trading launch

July 26, 2026
Crypto News

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Categories tes

  • Bitcoin
  • Blockchain
  • Business
  • Ethereum
  • Guide
  • Market
  • Regulation
  • Ripple

Tags

Act Bitcoin BTC CLARITY Coinbase Crypto data DeFi ETF ETFs ETH Ethereum Eyes Faces hit hits Hyperliquid Iran key launch launches Market markets million Network Onchain prediction price Push rally Ripple risk Solana Stablecoin stock Strategy support targets Token tokenized trading Trump U.S Warns XRP

Newsletter

[mc4wp_form]

  • About
  • FAQ
  • Support Forum
  • Landing Page
  • Contact Us

© 2017 JNews - Crafted with love by Jegtheme.

No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2018 JNews by Jegtheme.