Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

Bitcoin’s $60K rebound just collapsed as $427M in long liquidations followed sticky inflation data

June 25, 2026

Trump-backed American Bitcoin approves 1-for-15 reverse stock split

June 25, 2026

Inflation gauge hits 3-year high as Polymarket pegs July Fed hold at 77.5%

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

September 8, 2025Updated:September 8, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads
Share
Facebook Twitter LinkedIn Pinterest Email
ad



Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

Charles Guillemet, chief expertise officer at {hardware} pockets maker Ledger, warned on X on Monday {that a} large-scale provide chain assault is underway after the compromise of a good developer’s Node Package deal Supervisor (NPM) account.

Based on Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto pockets addresses in transactions. Meaning unsuspecting customers might ship funds on to the attacker with out realizing it.

Guillemet didn’t title the developer whose account he mentioned was compromised.

The incident underscores how deeply interconnected open-source software program is and why safety lapses in developer instruments can ripple into the crypto financial system virtually immediately.

There’s a large-scale provide chain assault in progress: the NPM account of a good developer has been compromised. The affected packages have already been downloaded over 1 billion occasions, which means your complete JavaScript ecosystem could also be in danger.

The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

“NPM is a software generally utilized in software program growth utilizing JavaScript, which makes integrating packages straightforward for builders,” mentioned Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they’ll slip malicious code into broadly used packages.

“The malicious code makes an attempt to empty customers by swapping addresses utilized in transaction or common on-chain exercise and changing them with the hacker’s tackle,” Guillemet added.

Guillemet confused that if any decentralized utility or software program pockets throughout any blockchain contains these JavaScript packages, then they might be compromised, and crypto customers might due to this fact lose their funds.

“The one positive technique to fight that is to make use of a {hardware} pockets with a safe display screen that helps Clear Signing,” mentioned Guillemet to CoinDesk. “This may enable the consumer to see precisely which addresses funds are being despatched to and guarantee they match the supposed addresses.”

“{Hardware} wallets with out safe screens and any pockets that does not help Clear signing is at excessive danger as it’s unimaginable to precisely confirm the transaction particulars are right,” he added.

“It is a chance to remind everybody: at all times confirm your transactions, by no means blind signal, use a {hardware} pockets with a safe display screen, and Clear Signal all the pieces,” Guillemet mentioned.

Learn extra: Ledger CTO Addresses Criticism of New Pockets Restoration Service





Source link

ad
attack CTO Downloads Hitting Ledger npm SupplyChain warns
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

Bitcoin’s $60K rebound just collapsed as $427M in long liquidations followed sticky inflation data

June 25, 2026

Trump-backed American Bitcoin approves 1-for-15 reverse stock split

June 25, 2026

Inflation gauge hits 3-year high as Polymarket pegs July Fed hold at 77.5%

June 25, 2026

Tokenized SpaceX Stock Liquidations Show Crypto Leverage Reaching Private Markets

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
Bitcoin’s $60K rebound just collapsed as $427M in long liquidations followed sticky inflation data
June 25, 2026
Trump-backed American Bitcoin approves 1-for-15 reverse stock split
June 25, 2026
Inflation gauge hits 3-year high as Polymarket pegs July Fed hold at 77.5%
June 25, 2026
Tokenized SpaceX Stock Liquidations Show Crypto Leverage Reaching Private Markets
June 25, 2026
SBI Expands Digital Asset Push With Bitbank Acquisition
June 25, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.