Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In March 2025, reporting identified malicious updates to 11 npm packages used in blockchain development. The listed releases contained install-time code described as capable of collecting environment variables, API keys, SSH keys, and access tokens. The reports did not establish how many systems were affected or how many credentials were stolen.

What happened in the March 2025 npm incident?

SecurityWeek reported on March 28, 2025, that multiple blockchain-development npm packages had been updated with obfuscated information-stealing scripts. The malicious code appeared in specific published releases; the reports do not show that every version of those packages was affected. SecurityWeek’s March 28 report attributed an approximate figure of 500,000 combined lifetime downloads to Sonatype. That number is not a count of infected systems, victims, or successful data thefts.

The Hacker News report excerpt quoted Sonatype researcher Ax Sharma saying: “Some of these packages have lived on npmjs.com for over 9 years, and provide legitimate functionality to blockchain developers.” A package’s age or previously legitimate use does not establish that a later registry release is safe.

Which npm package versions were reported as affected?

ECHO CTI’s March 31, 2025 bulletin lists these 11 package-and-version pairs. Check the exact version recorded in your lockfile or dependency tree; a matching package name alone does not tell you whether the reported release was installed.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Package Reported version
country-currency-map 2.1.8
bnb-javascript-sdk-nobroadcast 2.16.16
@bithighlander/bitcoin-cash-js-lib 5.2.2
eslint-config-travix 6.3.1
@crosswise-finance1/sdk-v2 0.1.21
@keepkey/device-protocol 7.13.3
@veniceswap/uikit 0.65.34
@veniceswap/eslint-config-pancake 1.6.2
babel-preset-travix 1.2.1
@travix/ui-themes 1.1.5
@coinmasters/types 4.8.16

Source: ECHO CTI bulletin, March 31, 2025. This is a historical incident list, not confirmation of current registry status or current safe-version guidance.

What could the malicious install scripts access?

ECHO CTI identified package/scripts/launch.js and package/scripts/diagnostic-report.js as malicious code paths and reported that they ran automatically during installation. The bulletin describes collection targeting environment variables, API keys, SSH keys, and access tokens. Such data may be available to processes running in a developer workstation or build environment, depending on what secrets that environment exposes.

The bulletin also identified a remote destination for collected data. Because that indicator comes from historical reporting, it should not be treated as proof that the destination is still active.

Was my npm package compromised?

The reports establish that the listed releases contained malicious code; they do not establish that a particular installation ran successfully, that data left a system, or that any specific account was compromised. To assess exposure, compare installed and resolved dependency versions with the list above, including transitive dependencies in the lockfile. If a listed version was installed in an environment with accessible secrets, follow your organization’s incident-response process, assess which credentials that environment could access, and consult current guidance from npm and the relevant maintainers.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How did the packages get hijacked?

The exact publishing or account-compromise method was not confirmed in the reports. SecurityWeek relayed Sonatype’s suggestion that old maintainer accounts may have been compromised, possibly through credential stuffing; this was a hypothesis, not a verified entry path or attribution.

ECHO CTI reported that it did not find the malicious code in the corresponding GitHub repositories even though it appeared in npm releases. That registry-versus-repository discrepancy does not explain how publishing access was obtained. SecurityWeek also noted that two packages had gone years without releases before the malicious updates, but a long quiet period alone is not evidence of compromise.

What the reporting does—and does not—show

  • Established: reporting identified 11 package versions with malicious install-time code and described credential and secret collection capability.
  • Approximate reach indicator: Sonatype’s roughly 500,000 combined lifetime-download figure, reported by SecurityWeek, is not an infection count.
  • Not established: the number of affected systems, successful exfiltrations, stolen credentials, or financial losses.
  • Not established: the confirmed initial-access method, the responsible individual or organization, or whether any listed release is currently available or considered safe.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.