The post Ledger CTO Warns Crypto Users appeared on BitcoinEthereumNews.com. A massive supply chain attack has compromised a developer’s NPM account. The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk. A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it. The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date. An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module. Crypto-Clipping: A New Malicious Threat The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time.  This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed. Impact on Developers and Crypto Users The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the… The post Ledger CTO Warns Crypto Users appeared on BitcoinEthereumNews.com. A massive supply chain attack has compromised a developer’s NPM account. The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk. A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it. The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date. An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module. Crypto-Clipping: A New Malicious Threat The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time.  This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed. Impact on Developers and Crypto Users The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the…

Ledger CTO Warns Crypto Users

  • A massive supply chain attack has compromised a developer’s NPM account.
  • The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk.

A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it.

The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date.

An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module.

Crypto-Clipping: A New Malicious Threat

The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time. 

This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed.

Impact on Developers and Crypto Users

The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the crypto users, the consequences are more direct. Transactions could be silently altered, draining funds without immediate detection. 

Significantly, Ledger’s CTO has outlined steps to minimize the risks with audit dependencies immediately. Also, the developers should inspect their projects and lockfiles to ensure no compromised versions remain. Pin all dependencies to the last known-safe versions.

Also, by using the hardware wallets with clear signing. With this, the users are protected as long as they carefully review and confirm every transaction before signing. Followed by refraining from on-chain transactions without hardware wallets, where users rely solely on software wallets are strongly advised to avoid conducting transactions.

Highlighted Crypto News
Fidelity launches FDIT token on Ethereum with $200M in U.S. Treasuries

Source: https://thenewscrypto.com/npm-supply-chain-breach-hits-the-javascript-ecosystem-ledger-cto-warns-crypto-users/

Market Opportunity
RealLink Logo
RealLink Price(REAL)
$0.079
$0.079$0.079
-0.27%
USD
RealLink (REAL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Buterin pushes Layer 2 interoperability as cornerstone of Ethereum’s future

Buterin pushes Layer 2 interoperability as cornerstone of Ethereum’s future

Ethereum founder, Vitalik Buterin, has unveiled new goals for the Ethereum blockchain today at the Japan Developer Conference. The plan lays out short-term, mid-term, and long-term goals touching on L2 interoperability and faster responsiveness among others. In terms of technology, he said again that he is sure that Layer 2 options are the best way […]
Share
Cryptopolitan2025/09/18 01:15
BlackRock Increases U.S. Stock Exposure Amid AI Surge

BlackRock Increases U.S. Stock Exposure Amid AI Surge

The post BlackRock Increases U.S. Stock Exposure Amid AI Surge appeared on BitcoinEthereumNews.com. Key Points: BlackRock significantly increased U.S. stock exposure. AI sector driven gains boost S&P 500 to historic highs. Shift may set a precedent for other major asset managers. BlackRock, the largest asset manager, significantly increased U.S. stock and AI sector exposure, adjusting its $185 billion investment portfolios, according to a recent investment outlook report.. This strategic shift signals strong confidence in U.S. market growth, driven by AI and anticipated Federal Reserve moves, influencing significant fund flows into BlackRock’s ETFs. The reallocation increases U.S. stocks by 2% while reducing holdings in international developed markets. BlackRock’s move reflects confidence in the U.S. stock market’s trajectory, driven by robust earnings and the anticipation of Federal Reserve rate cuts. As a result, billions of dollars have flowed into BlackRock’s ETFs following the portfolio adjustment. “Our increased allocation to U.S. stocks, particularly in the AI sector, is a testament to our confidence in the growth potential of these technologies.” — Larry Fink, CEO, BlackRock The financial markets have responded favorably to this adjustment. The S&P 500 Index recently reached a historic high this year, supported by AI-driven investment enthusiasm. BlackRock’s decision aligns with widespread market speculation on the Federal Reserve’s next moves, further amplifying investor interest and confidence. AI Surge Propels S&P 500 to Historic Highs At no other time in history has the S&P 500 seen such dramatic gains driven by a single sector as the recent surge spurred by AI investments in 2023. Experts suggest that the strategic increase in U.S. stock exposure by BlackRock may set a precedent for other major asset managers. Historically, shifts of this magnitude have influenced broader market behaviors as others follow suit. Market analysts point to the favorable economic environment and technological advancements that are propelling the AI sector’s momentum. The continued growth of AI technologies is…
Share
BitcoinEthereumNews2025/09/18 02:49
The 5 Best AI Sales Assistants for SDR Teams in 2026

The 5 Best AI Sales Assistants for SDR Teams in 2026

Sales teams are under pressure to generate more pipeline while response rates decline and headcount stays flat. Reps are expected to personalize outreach and spend
Share
AI Journal2026/01/18 06:14