• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Ledger CTO Warns of Major Supply Chain Attack Targeting JavaScript Ecosystem

September 9, 2025
in Australian Crypto News
Reading Time: 3min read
0 0
A A
0
Ledger CTO Warns of Major Supply Chain Attack Targeting JavaScript Ecosystem
0
SHARES
4
VIEWS
ShareShareShareShareShare
  • Ledger CTO Charles Guillemet has warned of a large-scale supply chain attack on the open-source Node Package Manager (NPM) ecosystem, where malicious code has been inserted into packages downloaded over one billion times.
  • The attack works by silently swapping crypto addresses to steal funds, and it exploits trusted distribution channels, making end-users vulnerable even if their personal systems are not compromised.
  • The compromise was a result of a phishing attack that tricked developers into clicking malicious links, and security experts are advising caution until the full scope of the attack is determined.

Ledger’s CTO, Charles Guillemet, issued a warning about what he described as a large-scale supply chain attack targeting the open-source ecosystem.

In a post to X on Monday, Guillemet said the Node Package Manager (NPM) account of a reputable developer had been compromised, with the attacker inserting malicious code into widely used packages that have been downloaded more than one billion times.

The malicious payload works by silently swapping crypto addresses on the fly to steal funds. If you use a hardware wallet, pay attention to every transaction before signing and you’re safe.

Charles Guillermet, CTO at Ledger

The exploit allows hackers to alter destination wallet addresses during transactions, redirecting funds without user awareness. Guillemet did not disclose which developer account was breached.

Related: Chainlink CEO Meets SEC, Signals Shift Toward On-Chain Asset Compliance

GCR contributor 0x_ultra reported that widely used packages such as Chalk, with over 2 billion weekly downloads, had been compromised and could “steal all your private keys.” 

The package maintainer confirmed the account compromise, stating that attackers used phishing emails impersonating the npmjs.com domain and threatening account lockouts to trick maintainers into clicking malicious links.

fellow devs, its fully over

chalk and projects with it as dependency (2b+ weekly downloads) have been pwned

packages which total 2B+ weekly downloads are compromised and stealing all your private keys pic.twitter.com/DntayqT42m

— ultra (@0x_ultra) September 8, 2025

The Systemic Risks of Open-Source Software

NPM is basically a backbone for JavaScript development, with code libraries integrated into countless websites and applications, including crypto platforms. A compromise at the package level can spread vulnerabilities across the entire industry.

Supply chain attacks differ from direct hacks of user accounts or wallets. Instead, they exploit trusted distribution channels, meaning end users can be exposed even if their personal systems remain uncompromised.

The tactic is similar to methods used in past incidents, such as the North Korea-linked exploit earlier this year that drained US$1.5B from Bybit by hijacking trusted systems to reroute funds.

At this point, it’s better to wait, as security experts have warned that until the full scope of the NPM compromise is identified, both developers and crypto users could be at risk.

Related: U.S., India Lead Global Crypto Adoption as APAC Transaction Volume Soars 69%


Credit: Source link

ShareTweetSendPinShare
Previous Post

Trump Family Nets $1.3B Boost from Bitcoin Ventures and DeFi Gains

Next Post

TON Price Prediction: $3.25 Short-Term Target, $6.20-8.00 Medium-Term Potential by October 2025

Next Post
Uniswap (UNI) Price Rallies 6.53% – Is Now the Time to Buy? Comprehensive Analysis & Trading Insights

TON Price Prediction: $3.25 Short-Term Target, $6.20-8.00 Medium-Term Potential by October 2025

You might also like

Standard Chartered Identifies Two Major Catalysts

Ripple Launches $750 Million Share Buyback, Boosting Valuation To $50 Billion

March 11, 2026
Is The Market Missing A Catalyst?

Is The Market Missing A Catalyst?

March 13, 2026
CGV Leads Expansion in Bitcoin Wallet Sector with UniSat Investment

AI Artist Mia Forrest Turns Machine Learning Into Physical Orchid Art

March 12, 2026
Mastercard Expands Crypto Push With New Network Integrating Binance and Ripple

Mastercard Expands Crypto Push With New Network Integrating Binance and Ripple

March 12, 2026
This Altcoin Gem Will Overtake Solana, Predicts Arthur Hayes

Arthur Hayes Says He Wouldn’t Buy Bitcoin Yet: Wait For This

March 11, 2026
Crypto Price Prediction Today 16 March – XRP, Pi Coin, PEPE

Crypto Price Prediction Today 16 March – XRP, Pi Coin, PEPE

March 16, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

XRP Moves Into ‘Scarce Zone’ As Exchange Supply Dries Up

XRP Moves Into ‘Scarce Zone’ As Exchange Supply Dries Up

March 17, 2026
XRP Price Prediction: Orderbook Shows 9:1 Buy Pressure on Coinbase — Is $2.25 Now the Path of Least Resistance?

XRP Price Prediction: Orderbook Shows 9:1 Buy Pressure on Coinbase — Is $2.25 Now the Path of Least Resistance?

March 17, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.