The electron-native-notify npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 23 Mar 2019 · npm
electron-native-notify 1.1.5 -> 1.1.6the package's main entry moduleOn 23 March 2019, the attacker published electron-native-notify 1.1.6 on npm with a malicious payload. The package was a dependency of the Agama cryptocurrency wallet from Komodo. The payload stole wallet seed phrases.
npm and Komodo put the value at risk at over 13 million US dollars. Version 1.1.5 was clean.
What happened
An attacker built trust with a harmless package and then added malicious code. According to npm, the attacker published a package that looked useful and later updated it with a malicious payload. Komodo states that the attacker spent several months making useful contributions before the code went in.
The timeline from npm and Snyk:
- 6 March 2019: version 1.0.0, not malicious.
- 8 March 2019: version 1.1.5 added as a dependency of EasyDEX-GUI, a part of the Agama wallet.
- 23 March 2019: malicious version 1.1.6.
- 13 April 2019: Agama 0.3.5 shipped with the compromised code (npm).
- 4 to 5 June 2019: npm removed the package and npm and Komodo disclosed the problem.
The code sent an HTTP GET request to a Heroku endpoint and downloaded a payload. The payload ran, then sent the wallet seed to the same server when a user entered it. Snyk also reports a later version, 1.2.0, deployed between 16 April and 11 May 2019.
Komodo reports that about one million KMD were taken, which is less than 1 percent of the circulating supply. The Komodo team moved about 8 million KMD and 96 BTC to safe storage. Only Komodo's Agama build was affected. The Verus Coin version was not. The KMD blockchain itself was not affected.
Vigilance compares the version you trust with the new one. Version 1.1.6 added code that fetches and runs a remote payload, and Vigilance reports the file that gained that capability. See the scan block below.
Affected versions
electron-native-notify1.1.6, and 1.2.0 per Snyk. Version 1.1.5 was the last clean release.- Komodo Agama wallet builds that included the dependency, including Agama 0.3.5 released on 13 April 2019.
Indicators of compromise
- Endpoint:
https://updatecheck.herokuapp.com/check. electron-native-notifyinpackage.json,package-lock.jsonor a build of EasyDEX-GUI.- An unexpected GET request to a Heroku address when a wallet app starts.
How to check
Search the tree for the package.
npm ls electron-native-notify
grep -rn "electron-native-notify" package.json package-lock.json yarn.lock 2>/dev/null
Also search proxy logs for updatecheck.herokuapp.com. For Agama, a user must check the wallet version and the date of the install.
What to do now
- Remove electron-native-notify from every project and rebuild.
- Agama users: Snyk advises moving all funds to a new address as soon as possible. Generate a new seed on a clean machine.
- Komodo asked affected users to file a Missing Funds Claim Form and to send a small test transaction from the old wallet to prove ownership.
- Block the Heroku endpoint.
- Run
npm audit. npm added automatic notices after this incident.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 12 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED package.json It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which electron-native-notify version was malicious?
Version 1.1.6, published on 23 March 2019, was malicious. Snyk also reports a later version, 1.2.0, with the malicious code. Version 1.1.5 was clean.
Did the electron-native-notify attack steal cryptocurrency?
Yes. It targeted seed phrases in the Komodo Agama wallet. Komodo reports about one million KMD were taken.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.