The post Ledger CTO Warns Crypto Users appeared on BitcoinEthereumNews.com. A massive supply chain attack has compromised a developer’s NPM account. The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk. A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it. The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date. An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module. Crypto-Clipping: A New Malicious Threat The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time.  This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed. Impact on Developers and Crypto Users The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the… The post Ledger CTO Warns Crypto Users appeared on BitcoinEthereumNews.com. A massive supply chain attack has compromised a developer’s NPM account. The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk. A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it. The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date. An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module. Crypto-Clipping: A New Malicious Threat The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time.  This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed. Impact on Developers and Crypto Users The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the…

Ledger CTO Warns Crypto Users

2025/09/09 17:29
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
  • A massive supply chain attack has compromised a developer’s NPM account.
  • The affected packages, with over 1B downloads, have put the JavaScript ecosystem at risk.

A major supply chain attack has thrown the JavaScript ecosystem into chaos, putting developers and crypto users on high alert. In response, Ledger’s CTO, Charles Guillemet, is urging hardware wallet owners to be extra vigilant and manually review every single transaction before approving it.

The breach started after the account of a well-known NPM developer was taken over, allowing attackers to publish malicious updates to widely used JavaScript packages. Together, these compromised packages have been downloaded more than a billion times. It makes the incident one of the most serious to date.

An attacker recently gained access to the qix NPM account, which is connected to some of the most fundamental libraries in the JavaScript ecosystem. This compromise affected several key packages, including chalk, strip-ansi, color-convert, color-name, and is-core-module.

Crypto-Clipping: A New Malicious Threat

The injected malware was designed to function as a crypto-clipper. The method of attack is both silent and dangerous; it swaps wallet addresses within network requests, hijacking cryptocurrency transactions in real time. 

This points out that the users attempting to send funds could unknowingly have their destination wallet addresses replaced with those controlled by the attacker. In addition, researchers are investigating whether the payload attempts to steal seed phrases from software wallets, though this has not yet been confirmed.

Impact on Developers and Crypto Users

The compromised developer packages could still introduce malicious code into projects. While the affected packages have since been patched or taken down. Also, the outdated versions may remain hidden in dependencies or lockfiles. This may imply that the systems are still exposed unless you do a thorough audit to find and remove them. Moreover, for the crypto users, the consequences are more direct. Transactions could be silently altered, draining funds without immediate detection. 

Significantly, Ledger’s CTO has outlined steps to minimize the risks with audit dependencies immediately. Also, the developers should inspect their projects and lockfiles to ensure no compromised versions remain. Pin all dependencies to the last known-safe versions.

Also, by using the hardware wallets with clear signing. With this, the users are protected as long as they carefully review and confirm every transaction before signing. Followed by refraining from on-chain transactions without hardware wallets, where users rely solely on software wallets are strongly advised to avoid conducting transactions.

Highlighted Crypto News
Fidelity launches FDIT token on Ethereum with $200M in U.S. Treasuries

Source: https://thenewscrypto.com/npm-supply-chain-breach-hits-the-javascript-ecosystem-ledger-cto-warns-crypto-users/

시장 기회
RealLink 로고
RealLink 가격(REAL)
$0.06712
$0.06712$0.06712
+1.25%
USD
RealLink (REAL) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!