qix npm Account Compromise

September 2025 phishing compromise of npm maintainer 'qix' that hijacked 18 ultra-popular packages (chalk, debug, ansi-styles, strip-ansi and more, 1B+ weekly downloads) to inject a browser-based crypto wallet address swapper.

discovered 2025-09-08

Objective

Hijack cryptocurrency transactions in the browser by swapping destination wallet addresses.

Packages

Indicators

Techniques

Read the full analysis →