Malicious Code Injection Threatens Popular npm Packages

A phishing attack has impacted renowned developer qix, leading to malicious code being injected into popular npm packages: chalk, strip-ansi, and color-convert. This attack exploited wallet functions, altered ETH/SOL transaction recipient addresses, and even replaced addresses in network responses. Users are encouraged to carefully verify details like recipient and amount information on their wallets before sending funds. Regularly reviewing recent transactions can also help identify any unexpected changes. Prioritizing the use of hardware wallets for high-value operations is crucial to minimizing potential risks during this incident.