• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 390969-180 | Support: +49 5251 390969-300
NoSpamProxy
  • PRODUCTS
    • Platforms
      • NoSpamProxy Cloud
      • NoSpamProxy Server
      • NoSpamProxy 25Reports
  • SOLUTIONS
    • Threat Protection
      • Protection against Spam, Phishing & Malware
      • AI Threat Detection
      • Isolated File Analysis
      • Microsoft 365 Mail Security
    • Secure Email Communication
      • Email Encryption
      • Automatic Certificate Management
      • Search for Public Keys
    • Productivity & Compliance
      • Sending Large Files
      • Email Disclaimer
  • INDUSTRIES
    • By Company Size
      • Large Companies
      • Small and Medium-Sized Enterprises
    • Regulated Industries
      • Public Institutions
      • Healthcare
      • Finance
      • Law
    • Success Stories
      • Testimonials
      • Awards
  • PARTNERS
    • Resellers
      • Finding Resellers
      • Become a Reseller
      • Become an MSP Partner
    • For Existing Partners
      • Partner Portal
      • Partner Trainings
      • NFR Licenses
  • RESOURCES
    • Support
      • Online Documentation
      • Forum
      • Support
    • Continuing Education
      • Training Courses
      • Webcasts
    • Knowledge
      • Blog
      • Newsletter
    • Downloads
      • NoSpamProxy Server
    • Events
      • Events
      • Webcasts
  • PRICING
  • CONTACT
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Information

Attack on node.js: No danger for NoSpamProxy customers

09.09.2025|Last edited:09.09.2025

On Monday, September 8, 2025, a significant attack on the software package supply chain for the widely used JavaScript runtime environment node.js was discovered. There is no danger for NoSpamProxy customers.

The attackers used spear phishing to gain access to a developer’s npm account and used the package manager to inject obfuscated malicious code into numerous popular packages. Based on current information, this appears to be the largest successful attack on npm to date.

About 20 of these are packages from the developer qix, which are downloaded more than two billion times a week. This has an impact on large parts of the Node.js universe. Furthermore, there are indications that packages from other developers may also have been contaminated with malware.

The malware discovered and investigated so far manipulates certain browser routines to intercept and manipulate data in the victim’s web browser. This affects both classic network traffic and traffic to and from programming interfaces (API). In addition, routines in any installed browser extensions for cryptocurrency wallets are modified.

The attackers’ goal is apparently to steal units of various cryptocurrencies. The malware waits for strings that look like wallet addresses and replaces the legitimate addresses with other addresses that are presumably controlled by the attacker.

Although we use npm in the development of NoSpamProxy, we do not use the compromised packages. There is therefore no danger for NoSpamProxy customers.

  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

NoSpamProxy Newsletter

Subscribe to Newsletter

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • News
  • Product
  • Product
  • Tech & Support
  • Tech & Support
  • Events
  • Events
Net at Work GmbH
Am Hoppenhof 32 A
33104 Paderborn
Tel. +49 5251 390969-000
Fax +49 5251 390969-009
www.nospamproxy.com
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • About us
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Finding resellers
  • Becoming a reseller
  • Becoming a MSP Partner
  • Newsletter Subscription
  • Order Certificates

Categories

  • All topics
  • News
  • Support
  • Product
  • Events
  • Updates

Latest News

  • NoSpamProxy Info Icon
    NoSpamProxy continues to evolve: greater focus on product and partner business01.09.2026 - 10:00
  • Info Icon
    Action Required: Renew Permissions for the Entra ID User Import14.08.2026 - 13:59
  • info icon
    NoSpamProxy and TLS Certificates: What Will Change by 202907.08.2026 - 10:00
IMPRINT • EULA • Privacy Policy • • © 2026 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to Instagram
Link to: VS-NfD and email security: What IT administrators need to know Link to: VS-NfD and email security: What IT administrators need to know VS-NfD and email security: What IT administrators need to knowVS-NfD Verschlusssache nur für den Dienstgebrauch 1200x627 Link to: Phishing with fake automobile brochures Link to: Phishing with fake automobile brochures Phishing mit gefaelschten Autokatalogen 800x800Phishing with fake automobile brochures
Scroll to top Scroll to top Scroll to top