/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Hacker gains access to the repo of Event-Stream, a JS library with 2M+ weekly downloads on npm, to inject BitPay's wallet apps with code that steals funds

Users of BitPay's Copay desktop and mobile wallet apps are affected.  An update has been released earlier today that doesn't contain the malicious code.

ZDNet Catalin Cimpanu

Context & Ripple Effects

This is the incident that put npm supply chain attacks on the map: an attacker took over the Event-Stream repository — a dependency with 2M+ weekly downloads — and used it to push fund-stealing code into BitPay's Copay wallet apps. BitPay's response was immediate, shipping a clean Copay update the same day the compromise surfaced.

What makes the story durable is how often the playbook repeats: CISA flagged malware in UAParser.js in 2021, attackers phished a maintainer to hit 18 npm packages with 2.6B+ weekly downloads in 2025, and Axios itself was compromised in 2026. Each escalation widened the blast radius, making this first attack the reference case for why registry trust became a security discipline.

First-order effects

  • BitPay's Copay desktop and mobile wallet users were directly exposed to code designed to steal funds, until BitPay pushed an update today that strips the malicious payload.
  • Every application pulling Event-Stream from npm inherited the malicious code automatically, turning a routine dependency install into a live theft vector for 2M+ weekly downloaders.

Second-order effects

  • Wallet and crypto app vendors depending on popular npm libraries face forced audits of their dependency trees, since the compromise shows a trusted transitive dependency can be weaponized against end-user funds.
  • npm's maintainer-trust model comes under pressure: the attack path ran through control of a widely-used repo, pushing registry operators and package owners toward tighter account and publish controls.

Third-order effects

  • If the pattern holds — UAParser.js, the 18-package phishing campaign, Axios, and the 600+ version Shai-Hulud flood all followed — single-maintainer open-source dependencies become a systemic attack surface requiring tooling, attestation, and eventually regulation rather than ad-hoc patching.
  • Software supply chain integrity shifts from an app-vendor problem to an ecosystem-level one, where a compromise of any high-download package is treated as potential infrastructure compromise.

The trend: Open-source package registries are becoming the preferred injection point for supply chain attacks, with each successive npm compromise reaching more downloads than the last.