• bitcoinBitcoin (BTC) $ 76,886.00
  • ethereumEthereum (ETH) $ 2,119.41
  • tetherTether (USDT) $ 0.999392
  • bnbBNB (BNB) $ 641.95
  • xrpXRP (XRP) $ 1.39
  • usd-coinUSDC (USDC) $ 0.999655
  • solanaSolana (SOL) $ 84.88
  • tronTRON (TRX) $ 0.356357
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.106095
  • whitebitWhiteBIT Coin (WBT) $ 56.72
  • usdsUSDS (USDS) $ 0.999786
  • hyperliquidHyperliquid (HYPE) $ 45.44
  • leo-tokenLEO Token (LEO) $ 10.08
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.250039
  • zcashZcash (ZEC) $ 530.84
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 375.56
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 385.58
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.52
  • canton-networkCanton (CC) $ 0.152752
  • the-open-networkToncoin (TON) $ 1.95
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.148542
  • usd1-wlfiUSD1 (USD1) $ 0.999736
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999608
  • ethena-usdeEthena USDe (USDE) $ 0.999747
  • litecoinLitecoin (LTC) $ 54.05
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • suiSui (SUI) $ 1.04
  • memecoreMemeCore (M) $ 3.18
  • avalanche-2Avalanche (AVAX) $ 9.16
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.089372
  • rainRain (RAIN) $ 0.007390
  • paypal-usdPayPal USD (PYUSD) $ 0.999938
  • usdt0USDT0 (USDT0) $ 0.998824
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • crypto-com-chainCronos (CRO) $ 0.069281
  • global-dollarGlobal Dollar (USDG) $ 0.999872
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,528.77
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 259.08
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • uniswapUniswap (UNI) $ 3.42
  • pax-goldPAX Gold (PAXG) $ 4,529.51
  • mantleMantle (MNT) $ 0.633863
  • polkadotPolkadot (DOT) $ 1.23
  • nearNEAR Protocol (NEAR) $ 1.50
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.059754
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.998234
  • okbOKB (OKB) $ 81.97
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.648229
  • ondo-financeOndo (ONDO) $ 0.339551
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • skySky (SKY) $ 0.069450
  • pi-networkPi Network (PI) $ 0.148902
  • ripple-usdRipple USD (RLUSD) $ 0.999826
  • pepePepe (PEPE) $ 0.000004
  • usddUSDD (USDD) $ 0.998974
  • internet-computerInternet Computer (ICP) $ 2.56
  • ethereum-classicEthereum Classic (ETC) $ 8.85
  • bitget-tokenBitget Token (BGB) $ 1.98
  • aaveAave (AAVE) $ 88.28
  • bfusdBFUSD (BFUSD) $ 0.998600
  • morphoMorpho (MORPHO) $ 1.76
  • quant-networkQuant (QNT) $ 74.98
  • usdtbUSDtb (USDTB) $ 0.999190
  • kucoin-sharesKuCoin (KCS) $ 7.92
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • cosmosCosmos Hub (ATOM) $ 2.07
  • united-stablesUnited Stables (U) $ 0.999301
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.08
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.090693
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.87
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • algorandAlgorand (ALGO) $ 0.107825
  • ethenaEthena (ENA) $ 0.104189
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.033705
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • render-tokenRender (RENDER) $ 1.78
  • nexoNEXO (NEXO) $ 0.859672
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • stable-2​​Stable (STABLE) $ 0.036940
  • worldcoin-wldWorldcoin (WLD) $ 0.235497
  • wbnbWrapped BNB (WBNB) $ 759.61
  • flare-networksFlare (FLR) $ 0.008916
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.928796
  • justJUST (JST) $ 0.088599
  • gatechain-tokenGate (GT) $ 7.00
  • filecoinFilecoin (FIL) $ 0.945161
  • arbitrumArbitrum (ARB) $ 0.116188
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • venice-tokenVenice Token (VVV) $ 14.53
  • jupiter-exchange-solanaJupiter (JUP) $ 0.196003
  • dexeDeXe (DEXE) $ 13.89
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • xdce-crowd-saleXDC Network (XDC) $ 0.031282
  • beldexBeldex (BDX) $ 0.078739
  • pump-funPump.fun (PUMP) $ 0.001700
  • ghoGHO (GHO) $ 0.999364
  • vechainVeChain (VET) $ 0.006698
  • hash-2Provenance Blockchain (HASH) $ 0.010630
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.998080
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ousgOUSG (OUSG) $ 115.25
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.43
  • dashDash (DASH) $ 42.00
  • yldsYLDS (YLDS) $ 0.999978
  • clbtcclBTC (CLBTC) $ 76,920.00
  • bonkBonk (BONK) $ 0.000006
  • midnight-3Midnight (NIGHT) $ 0.031623
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008285
  • kite-2Kite (KITE) $ 0.221398
  • a7a5A7A5 (A7A5) $ 0.012816
  • true-usdTrueUSD (TUSD) $ 0.999252
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • official-trumpOfficial Trump (TRUMP) $ 2.08
  • chilizChiliz (CHZ) $ 0.046055
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • apxusdapxUSD (APXUSD) $ 0.999871
  • tbtctBTC (TBTC) $ 70,942.00
  • injective-protocolInjective (INJ) $ 4.63
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.698631
  • euro-coinEURC (EURC) $ 1.16
  • humanityHumanity (H) $ 0.245944
  • blockstackStacks (STX) $ 0.235495
  • edgexedgeX (EDGE) $ 1.24
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000077
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.188698
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.422710
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.17
  • adi-tokenADI (ADI) $ 4.00
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • sei-networkSei (SEI) $ 0.060559
  • usdgoUSDGO (USDGO) $ 0.999682
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996988
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • aerodrome-financeAerodrome Finance (AERO) $ 0.407526
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • usxUSX (USX) $ 0.999530
  • sun-tokenSun Token (SUN) $ 0.019664
  • unibaseUnibase (UB) $ 0.149824
  • tezosTezos (XTZ) $ 0.338266
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • build-onBUILDon (B) $ 0.361399
  • siren-2Siren (SIREN) $ 0.495297
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • labLAB (LAB) $ 4.69
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • celestiaCelestia (TIA) $ 0.383975
  • kinesis-goldKinesis Gold (KAU) $ 147.57
  • billions-networkBillions Network (BILL) $ 0.144268
  • curve-dao-tokenCurve DAO (CRV) $ 0.231373
  • spx6900SPX6900 (SPX) $ 0.360598
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • ether-fiEther.fi (ETHFI) $ 0.380362
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • layerzeroLayerZero (ZRO) $ 1.28
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • monadMonad (MON) $ 0.027055
  • skyaiSkyAI (SKYAI) $ 0.313665
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • gnosisGnosis (GNO) $ 119.08
  • pendlePendle (PENDLE) $ 1.83
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • hastra-primePRIME (PRIME) $ 1.04
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • kaiaKaia (KAIA) $ 0.052960
  • doublezeroDoubleZero (2Z) $ 0.088187
  • conflux-tokenConflux (CFX) $ 0.058894
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • bitcoin-svBitcoin SV (BSV) $ 15.09
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Axios supply chain attack raises risk to crypto wallets

0 0


Axios, one of the most popular JavaScript libraries, may be compromised and involved in a crypto wallet attack. The npm package attack is becoming more common, directly attacking projects, developers, and end users.

An Axios npm package was published to the official JavaScript library, and unpublished just hours later. On-chain security experts intercepted the attack, which was active for around three hours.

@npmjs @GHSecurityLab there is an active supply chain attack on axios@1.14.1 which pulls in a malicious package published today – plain-crypto-js@4.2.1 – someone took over a maintainer account for Axios

— Maxwell (@mvxvvll) March 31, 2026

The npm packages were compromised through the credentials of @jasonsaayman, as researchers still looked for signs that the account was compromised. The affected packages were identified as axios@1.14.1 and axios@0.30.4.

As Cryptopolitan reported earlier, npm attacks often target crypto wallets and are especially risky for decentralized projects with large team holdings.

What happened in the Axios npm attack?

StepSecurity was among the first to identify the issue. Two malicious versions of the Axios HTTP client library were published through the compromised credentials of a lead Axios maintainer, bypassing the normal publishing pipeline on GitHub.

According to StepSecurity, this was the most sophisticated attack against a widely used top-10 npm package. The malicious package version injects a new dependency, plain-crypto-js@4.2.1, which is not imported in the axios source code. The dependency runs a post-install script, active on all operating systems.

After using the npm, the client is infected with a remote access trojan dropper, which has a live server and delivers the payloads. The malware also deletes itself and replaces the suspect .json with a clean version to evade detection.

Which types of projects were affected?

The npm packages were among the most popular, with up to 100M weekly downloads. However, at this point, there are no reports of unauthorized crypto movement. Previously, an npm attack led to only $1,000 of crypto losses from obscure tokens.

The only way to limit malicious npm is to track versions and not allow automated upgrades, or check new versions for potential malicious uploads.

New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads.

Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily)…

— Andrej Karpathy (@karpathy) March 31, 2026

Researchers also discovered two additional malicious packages delivering payloads the same way – @shadanai/openclaw and @qqbrowser/openclaw-qbot. The attack follows the LiteLLM malicious code injection by just a week.

There is no report of Web3 or OpenClaw projects being affected or any crypto stolen, for the duration of the attack. However, warnings were issued that npm attacks may now become the norm, either through stolen credentials or unauthorized publishers. The threat follows previous warnings on malicious code using the OpenClaw skill platform.

The packages are not limited to Web3 or bot projects, and may affect any payloads linked to crypto wallets. The loss of trust in npm and pip installs for Python may also erode the general trust in the library ecosystem, with calls for a more secure upload path.

The usage of AI agents may also lead to indiscriminate package downloading, spreading the threat. The actual effects on crypto wallets may not be immediate, but they still potentially expose wallet data.



Source link

Leave A Reply

Your email address will not be published.