NPM Supply Chain Attack Update

馃敀 Polygon dodges bullet

By Polygon
Sep 11, 2025, 4:10 PM
twitter

Polygon confirms safety after NPM supply chain attack targeting debug and chalk packages.​

  • Polygon PoS and Agglayer code libraries not impacted
  • No vulnerable package versions in use
  • Team continues active monitoring

Security reminders:

  • Verify websites before interacting
  • Avoid suspicious links
  • Triple-check addresses and transactions

Layer3 also confirmed they remain unaffected by the exploit.​

Technical details

Sources

Our team has been actively monitoring the NPM supply chain attack. We have determined Polygon PoS and Agglayer code libraries are not impacted and do not use any vulnerable versions of the affected packages. Remember: Always stay vigilant when interacting with apps. Verify

Charles Guillemet
Charles Guillemet
@P3b7_

馃毃 There鈥檚 a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works

482
Reply
Read more about Polygon

Polygon USDT0 Supply Hits $1.4B All-Time High

**Polygon's native USDT0 deployment reaches new milestone** with supply hitting an all-time high of $1.4 billion USD. The achievement follows Polygon's recent upgrade to native USDT0 deployment, enhancing the network's stablecoin infrastructure. This milestone reinforces Polygon's position as a leading platform for borderless payments and stablecoin adoption. **Key highlights:** - USDT0 supply on Polygon: $1.4B ATH - Native deployment upgrade recently completed - Strengthens Polygon's stablecoin ecosystem The growth demonstrates increasing adoption of Polygon's infrastructure for cross-border transactions and digital payments, particularly as stablecoins become essential tools for global financial inclusion.

馃幃 Pok茅mon Cards Go Digital

**Courtyard.io** launches tokenized trading cards on Polygon, covering Pok茅mon, sports, and comics. **Key features:** - Mint, trade, and redeem digital card packs - Physical redemption available anytime, anywhere - RWA (Real World Assets) integration Users can now pair legendary sports cards with tokenized Pok茅mon collections. The platform bridges physical collectibles with blockchain technology, allowing collectors to trade digital versions while maintaining the option to claim physical cards. This represents a significant step in bringing traditional collectibles into the web3 ecosystem through tokenization.

POL Celebrates One Year Anniversary

**Polygon's POL token marks its first anniversary** as the network's native gas and staking token. The **MATIC to POL migration is 99% complete**, with POL now powering every transaction, block, and application across the Polygon ecosystem. Key highlights: - POL serves as both gas and staking token - Powers the entire Polygon PoS network - Supports scaling of payments and real-world assets (RWAs) - Foundation for Polygon's aggregated roadmap Users still holding MATIC on Ethereum can upgrade to POL through the [Polygon Portal](https://portal.polygon.technology/pol-upgrade). The milestone reflects Polygon's continued focus on network optimization and ecosystem growth.

Polygon Adds migrateTo() Function for Final MATIC-to-POL Migration Phase

Polygon introduces a new **migrateTo()** function that allows users to migrate MATIC tokens directly to another wallet address during the POL upgrade process. **Key Features:** - Direct wallet-to-wallet migration capability - Enables exchanges and institutions to handle migrations on behalf of users - Streamlines the final migration steps **Migration Progress:** With **99.18% of the migration already complete**, this new feature addresses the remaining technical hurdles for the final users and institutional holders. **Benefits:** - Simplified process for exchanges - Reduced friction for institutional migrations - Enhanced flexibility for end users This addition represents the final technical piece needed to complete Polygon's transition from MATIC to POL as the network's native token.