A digital worm attacks npm packages in a supply chain attack, stealing cryptocurrency keys and API credentials.
Blockchain News

Critical npm Worm SANDWORM_MODE Steals Crypto Keys in Devastating Supply Chain Attack

Global, April 2025: A sophisticated, self-replicating worm is actively compromising developer environments worldwide by infiltrating the npm registry. Dubbed SANDWORM_MODE, this malicious software targets over 19 packages to harvest sensitive data, including cryptocurrency private keys, BIP39 mnemonics, digital wallet files, and API keys for large language models. This represents a live and ongoing npm supply […]