The post Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads appeared on BitcoinEthereumNews.com. Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account. According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it. Guillemet did not name the developer whose account he said was compromised. The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly. 🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works… — Charles Guillemet (@P3b7_) September 8, 2025 “NPM is a tool commonly used in software development using JavaScript, which makes integrating packages easy for developers,” said Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they can slip malicious code into widely used packages. “The malicious code attempts to drain users by swapping addresses used in transaction or general on-chain activity and replacing them with the hacker’s address,” Guillemet added. Guillemet stressed that if any decentralized application or software wallet across any blockchain includes these JavaScript packages, then they could be compromised, and crypto users could therefore lose their funds. “The only sure way to combat this is to use a hardware wallet with a secure screen that supports Clear Signing,” said Guillemet to CoinDesk. “This will allow the user to see exactly which addresses funds are being sent to and… The post Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads appeared on BitcoinEthereumNews.com. Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account. According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it. Guillemet did not name the developer whose account he said was compromised. The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly. 🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works… — Charles Guillemet (@P3b7_) September 8, 2025 “NPM is a tool commonly used in software development using JavaScript, which makes integrating packages easy for developers,” said Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they can slip malicious code into widely used packages. “The malicious code attempts to drain users by swapping addresses used in transaction or general on-chain activity and replacing them with the hacker’s address,” Guillemet added. Guillemet stressed that if any decentralized application or software wallet across any blockchain includes these JavaScript packages, then they could be compromised, and crypto users could therefore lose their funds. “The only sure way to combat this is to use a hardware wallet with a secure screen that supports Clear Signing,” said Guillemet to CoinDesk. “This will allow the user to see exactly which addresses funds are being sent to and…

Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account.

According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it.

Guillemet did not name the developer whose account he said was compromised.

The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly.

“NPM is a tool commonly used in software development using JavaScript, which makes integrating packages easy for developers,” said Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they can slip malicious code into widely used packages.

“The malicious code attempts to drain users by swapping addresses used in transaction or general on-chain activity and replacing them with the hacker’s address,” Guillemet added.

Guillemet stressed that if any decentralized application or software wallet across any blockchain includes these JavaScript packages, then they could be compromised, and crypto users could therefore lose their funds.

“The only sure way to combat this is to use a hardware wallet with a secure screen that supports Clear Signing,” said Guillemet to CoinDesk. “This will allow the user to see exactly which addresses funds are being sent to and ensure they match the intended addresses.”

“Hardware wallets without secure screens and any wallet that doesn’t support Clear signing is at high risk as it is impossible to accurately verify the transaction details are correct,” he added.

“It’s an opportunity to remind everyone: always verify your transactions, never blind sign, use a hardware wallet with a secure screen, and Clear Sign everything,” Guillemet said.

Read more: Ledger CTO Addresses Criticism of New Wallet Recovery Service

Source: https://www.coindesk.com/tech/2025/09/08/ledger-cto-warns-of-npm-supply-chain-attack-hitting-1b-downloads

Market Opportunity
null Logo
null Price(null)
--
----
USD
null (null) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

ETHZilla unleashes fresh $350M war chest for Ethereum bets

ETHZilla unleashes fresh $350M war chest for Ethereum bets

                                                                               ETHZilla CEO McAndrew Rudisill said the company’s strategy is to deploy Ether on the Ethereum network through layer-2 protocols and tokenizing real-world assets.                     Ether treasury company ETHZilla is looking to raise another $350 million through new convertible bonds, with funds marked for more Ether purchases and generating yield through investments in the ecosystem. ETHZilla chairman and CEO McAndrew Rudisill said on Monday that the company’s strategy is to deploy Ether (ETH) in “cash-flowing assets” on the Ethereum network through layer-2 protocols and tokenizing real-world assets. A growing number of digital asset companies are moving past simply holding crypto and looking to generate yields through active participation in the ecosystem, which crypto executives told Cointelegraph in August, could help spark a DeFi Summer 2.0.Read more
Share
Coinstats2025/09/23 10:39
US Leads With $2.05B in Crypto Fund Inflows, CoinShares Reports

US Leads With $2.05B in Crypto Fund Inflows, CoinShares Reports

TLDR Crypto investment products recorded $2.17 billion in inflows, marking the strongest weekly performance since October 2025. Bitcoin dominated the inflows, attracting
Share
Coincentral2026/01/19 19:11
Judge Dismisses Trump’s $15 Billion Lawsuit Against NY Times

Judge Dismisses Trump’s $15 Billion Lawsuit Against NY Times

The post Judge Dismisses Trump’s $15 Billion Lawsuit Against NY Times appeared on BitcoinEthereumNews.com. Key Points: The judge dismisses Trump’s lawsuit against The New York Times. Potential repercussions for Truth Social and TRUMP coin. No immediate crypto market shifts tied to the lawsuit. A US judge dismissed Donald Trump’s $15 billion lawsuit against The New York Times, citing violations of federal rules, and permitted an amendment to the complaint. No immediate impact on Trump’s cryptocurrency ventures has been observed, but potential implications for his crypto brand and market perception remain under scrutiny. $15B Lawsuit Dismissal Sparks Speculation on TRUMP Coin Impact Donald Trump filed the lawsuit on September 16th, claiming The New York Times harmed his business ventures, including Truth Social and TRUMP cryptocurrency. News of the dismissal emerged as the court required more clarity in the complaint. Despite the dismissal, no immediate market reactions in the cryptocurrency sphere have been noted. The financial and digital impacts remain uncertain as the case progresses through legal avenues and potential amendments. Reactions have been measured, with stakeholders awaiting further developments. The judge’s comment: “The complaint is not a public forum for insults or a protected platform for attacking opponents.” underscores the need for precision in legal filings. TRUMP Token Trading Volumes Drop Amid Legal Turmoil Did you know? Trump’s legal issues contrast with past cases such as Elon Musk’s lawsuits, which temporarily influenced market sentiments, demonstrating unique crypto-law dynamics. CoinMarketCap data shows that as of September 20, 2025, the OFFICIAL TRUMP TRUMP token trades at $8.47 with a market cap of $1.69 billion. Trading volume has decreased by 37.33% over the past 24 hours, despite being the focus of ongoing developments. OFFICIAL TRUMP(TRUMP), daily chart, screenshot on CoinMarketCap at 20:36 UTC on September 20, 2025. Source: CoinMarketCap The Coincu research team notes that legal outcomes could influence regulatory perceptions of crypto projects tied to public figures.…
Share
BitcoinEthereumNews2025/09/21 04:41