Hacker gains access to the repo of Event-Stream, a JS library with 2M+ weekly downloads on npm, to inject BitPay's wallet apps with code that steals funds
Users of BitPay's Copay desktop and mobile wallet apps are affected. An update has been released earlier today that doesn't contain the malicious code.
Context & Ripple Effects
This is the incident that put npm supply chain attacks on the map: an attacker took over the Event-Stream repository — a dependency with 2M+ weekly downloads — and used it to push fund-stealing code into BitPay's Copay wallet apps. BitPay's response was immediate, shipping a clean Copay update the same day the compromise surfaced.
What makes the story durable is how often the playbook repeats: CISA flagged malware in UAParser.js in 2021, attackers phished a maintainer to hit 18 npm packages with 2.6B+ weekly downloads in 2025, and Axios itself was compromised in 2026. Each escalation widened the blast radius, making this first attack the reference case for why registry trust became a security discipline.
First-order effects
- BitPay's Copay desktop and mobile wallet users were directly exposed to code designed to steal funds, until BitPay pushed an update today that strips the malicious payload.
- Every application pulling Event-Stream from npm inherited the malicious code automatically, turning a routine dependency install into a live theft vector for 2M+ weekly downloaders.
Second-order effects
- Wallet and crypto app vendors depending on popular npm libraries face forced audits of their dependency trees, since the compromise shows a trusted transitive dependency can be weaponized against end-user funds.
- npm's maintainer-trust model comes under pressure: the attack path ran through control of a widely-used repo, pushing registry operators and package owners toward tighter account and publish controls.
Third-order effects
- If the pattern holds — UAParser.js, the 18-package phishing campaign, Axios, and the 600+ version Shai-Hulud flood all followed — single-maintainer open-source dependencies become a systemic attack surface requiring tooling, attestation, and eventually regulation rather than ad-hoc patching.
- Software supply chain integrity shifts from an app-vendor problem to an ecosystem-level one, where a compromise of any high-download package is treated as potential infrastructure compromise.
The trend: Open-source package registries are becoming the preferred injection point for supply chain attacks, with each successive npm compromise reaching more downloads than the last.