The post Ledger CTO Warns Crypto Users appeared on BitcoinEthereumNews.com. A massive supply chain attack has compromised a developer’s NPM account. The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk. A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it. The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date. An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module. Crypto-Clipping: A New Malicious Threat The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time.  This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed. Impact on Developers and Crypto Users The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the… The post Ledger CTO Warns Crypto Users appeared on BitcoinEthereumNews.com. A massive supply chain attack has compromised a developer’s NPM account. The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk. A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it. The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date. An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module. Crypto-Clipping: A New Malicious Threat The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time.  This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed. Impact on Developers and Crypto Users The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the…

Ledger CTO Warns Crypto Users

  • A massive supply chain attack has compromised a developer’s NPM account.
  • The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk.

A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it.

The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date.

An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module.

Crypto-Clipping: A New Malicious Threat

The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time. 

This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed.

Impact on Developers and Crypto Users

The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the crypto users, the consequences are more direct. Transactions could be silently altered, draining funds without immediate detection. 

Significantly, Ledger’s CTO has outlined steps to minimize the risks with audit dependencies immediately. Also, the developers should inspect their projects and lockfiles to ensure no compromised versions remain. Pin all dependencies to the last known-safe versions.

Also, by using the hardware wallets with clear signing. With this, the users are protected as long as they carefully review and confirm every transaction before signing. Followed by refraining from on-chain transactions without hardware wallets, where users rely solely on software wallets are strongly advised to avoid conducting transactions.

Highlighted Crypto News
Fidelity launches FDIT token on Ethereum with $200M in U.S. Treasuries

Source: https://thenewscrypto.com/npm-supply-chain-breach-hits-the-javascript-ecosystem-ledger-cto-warns-crypto-users/

Market Opportunity
RealLink Logo
RealLink Price(REAL)
$0.07881
$0.07881$0.07881
-0.51%
USD
RealLink (REAL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32
Edges higher ahead of BoC-Fed policy outcome

Edges higher ahead of BoC-Fed policy outcome

The post Edges higher ahead of BoC-Fed policy outcome appeared on BitcoinEthereumNews.com. USD/CAD gains marginally to near 1.3760 ahead of monetary policy announcements by the Fed and the BoC. Both the Fed and the BoC are expected to lower interest rates. USD/CAD forms a Head and Shoulder chart pattern. The USD/CAD pair ticks up to near 1.3760 during the late European session on Wednesday. The Loonie pair gains marginally ahead of monetary policy outcomes by the Bank of Canada (BoC) and the Federal Reserve (Fed) during New York trading hours. Both the BoC and the Fed are expected to cut interest rates amid mounting labor market conditions in their respective economies. Inflationary pressures in the Canadian economy have cooled down, emerging as another reason behind the BoC’s dovish expectations. However, the Fed is expected to start the monetary-easing campaign despite the United States (US) inflation remaining higher. Investors will closely monitor press conferences from both Fed Chair Jerome Powell and BoC Governor Tiff Macklem to get cues about whether there will be more interest rate cuts in the remainder of the year. According to analysts from Barclays, the Fed’s latest median projections for interest rates are likely to call for three interest rate cuts by 2025. Ahead of the Fed’s monetary policy, the US Dollar Index (DXY), which tracks the Greenback’s value against six major currencies, holds onto Tuesday’s losses near 96.60. USD/CAD forms a Head and Shoulder chart pattern, which indicates a bearish reversal. The neckline of the above-mentioned chart pattern is plotted near 1.3715. The near-term trend of the pair remains bearish as it stays below the 20-day Exponential Moving Average (EMA), which trades around 1.3800. The 14-day Relative Strength Index (RSI) slides to near 40.00. A fresh bearish momentum would emerge if the RSI falls below that level. Going forward, the asset could slide towards the round level of…
Share
BitcoinEthereumNews2025/09/18 01:23
Zero Knowledge Proof Sparks 300x Growth Discussion! Bitcoin Cash & Ethereum Cool Off

Zero Knowledge Proof Sparks 300x Growth Discussion! Bitcoin Cash & Ethereum Cool Off

Explore how Bitcoin Cash and Ethereum move sideways while Zero Knowledge Proof (ZKP) gains notice with a live presale auction, working infra, shipping Proof Pods
Share
CoinLive2026/01/18 07:00