Ledger’s Chief Technology Officer Charles Guillemet has sounded an alarm over what he described as one of the most serious supply chain attacks ever to hit the JavaScript ecosystem.Ledger’s Chief Technology Officer Charles Guillemet has sounded an alarm over what he described as one of the most serious supply chain attacks ever to hit the JavaScript ecosystem.

Global Crypto Warning: Ledger Flags Major JavaScript Supply Chain Breach

2025/09/09 16:09
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Ledger’s Chief Technology Officer Charles Guillemet has sounded an alarm over what he described as one of the most serious supply chain attacks ever to hit the JavaScript ecosystem.  

Ledger Issues Urgent Warning

On Monday, Ledger CTO Guillemet posted on X that the npm account of a reputable open-source maintainer had been compromised, leading to malicious updates across widely used software libraries. 

He wrote,

He stressed that hardware wallet users remain secure if they verify every transaction, but advised all others to stop conducting blockchain transactions temporarily.

Malicious Updates to Widely Used Packages

The breach occurred on September 8 when hackers gained access to the npm account of Josh Goldberg, known as “Qix.” Attackers published corrupted versions of 18 packages, including chalk, debug, strip-ansi, and color-convert, which collectively account for more than 2.6 billion weekly downloads and are embedded in core developer tools like Babel and ESLint.

Researchers discovered that the injected code carried “crypto-clipper” malware designed to intercept browser functions. The payload swaps legitimate wallet addresses with attacker-controlled ones and, in some cases, hijacks wallet communications to modify transactions before signatures are applied. The malware was first detected after a build error revealed hidden obfuscated code.

Sophisticated Attack Strategy

Analysis showed the malware was engineered with dual tactics: passively replacing wallet addresses with lookalikes, while actively intercepting and altering transactions on browser-based wallets such as MetaMask. This layered approach allowed attackers to redirect funds seamlessly, often without users realizing.

Investigations suggest the breach originated from a phishing attack on npm maintainers. Fraudulent emails, posing as official npm security notices, instructed recipients to update two-factor authentication or risk account suspension. Victims who followed the link were directed to a fake login page, allowing attackers to seize credentials and infiltrate Goldberg’s account.

Once inside, the attackers distributed malicious versions of the core packages, effectively weaponizing software tools relied upon by millions. Security firm Aikido noted that the code functioned as a browser interceptor, capable of rewriting payment destinations, altering API calls, and tampering with website content.

Ongoing Fallout and Industry Concerns

Although npm has removed many of the compromised versions, security experts warn that hidden transitive dependencies make it difficult to fully contain the attack. Developers are being urged to audit projects, pin known-safe package versions, and rebuild lockfiles immediately.

The incident underscores the fragility of the open-source ecosystem, which depends heavily on trust between maintainers and developers. With wallet addresses linked to stolen funds already surfacing on-chain, researchers are calling the attack one of the most severe in the history of the JavaScript ecosystem.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice

시장 기회
Major 로고
Major 가격(MAJOR)
$0.06198
$0.06198$0.06198
-1.03%
USD
Major (MAJOR) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!