Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Ledger CTO raises alarm over NPM supply chain attack targeting crypto users

Ledger CTO raises alarm over NPM supply chain attack targeting crypto users

Crypto.NewsCrypto.News2025/09/08 16:00
By:By Grace AbidemiEdited by Dorian Batycka

A major supply chain attack has rocked the crypto ecosystem, threatening users globally. Ledger’s CTO Charles Guillemet is sounding the alarm, urging caution and hardware wallet use.

Summary
  • Ledger CTO Charles Guillemet alerts users to a widespread JavaScript supply chain attack silently swapping crypto wallet addresses.
  • 18 popular NPM packages were compromised. Libraries like chalk and debug were injected with malware after a developer’s account was hijacked.
  • Just $497 stolen so far, but over 2 billion downloads means many dApps and wallets are potentially exposed.
  • Protocols like Uniswap, Jupiter, and wallet providers like MetaMask have assured users that their funds are safe.

The attack, which began with a hacked Node Package Manager (NPM) account, has already affected billions of downloads and endangered the security of millions of dApps and crypto transactions.

“The NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times,” Guillemet warned.

https://twitter.com/p3b7_/status/1965094840959410230?s=12

He further explained that the malware operates as a crypto clipper, stealthily hijacking wallet addresses during transactions to redirect funds to the attacker’s wallets. Guillemet urged users to be extra cautious, especially those not using hardware wallets.

“If you use a hardware wallet, pay attention to every transaction before signing and you’re safe. If you don’t, refrain from making any on-chain transactions for now,” he advised.

NPM hack: How the breach happened 

Reports revealed that 18 popular NPM packages were found to be compromised, including high-profile packages such as ‘chalk’, ‘debug’, and ‘strip-ansi.’ The attack, which happened on Sept 8, is among the largest in recent history, impacting libraries with a total of more than 2 billion weekly downloads.

The attack allegedly began with a phishing email impersonating official NPM support. The target was Qix-, a respected developer whose NPM account was hijacked, enabling attackers to inject malicious updates into popular JavaScript libraries.

Once installed, the malicious payload silently replaces copied crypto addresses with lookalike ones controlled by the hacker. This technique, powered by Levenshtein distance logic, tricks unsuspecting users into sending funds to the wrong addresses.

One main wallet address linked to the attack was highlighted by researchers, though they flagged additional wallets believed to be connected.

Although Charles said it is not clear whether the attacker is also stealing seeds of software wallets at this point directly, recent reports have shed light on the damage. Researcher Rani Haddad categorized the wallets of the attacker on Arkham as an entity called NPM attack. The data indicates that the attacker was able to steal $497.96 at press time.

Ledger CTO raises alarm over NPM supply chain attack targeting crypto users image 0 The wallets of the attacker | Source: Arkham

Although the direct financial effect is not that significant, the possible magnitude is immense considering the popularity of the affected packages.

Community response and prevention 

A number of projects and protocols, such as Uniswap, SUI, and Jupiter, have affirmed that they are not affected but have advised caution. Cryptocurrency wallets such as Ledger and MetaMask assured users of multi-layered security measures.

Meanwhile, the NPM supply chain hack was not the only major security event on Sept. 8. Swiss crypto wealth platform SwissBorg reported a $41 million exploit via a partner API, affecting 1% of users. Additionally, the Ethereum L2 project Kinto announced its shutdown after a July exploit drained 577 ETH, leaving the team unable to secure funding.

This wave of attacks is an indicator of the increasing complexity of crypto threats. Going forward, users, developers, and platforms need to embrace more secure practices and rigorous package audits.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Golden Ten Data Exclusive: Full Text of the US August CPI Report

In August, the US CPI rose by 0.4% month-on-month and increased to 2.9% year-on-year, with housing and food being the main drivers. Inflationary pressure is intensifying again. The full report is as follows.

Jin102025/09/11 15:53

Proof of Humanity and the "Dead Internet"

Don't let those "tin cans" control you or take away your tokens.

ForesightNews 速递2025/09/11 10:43
Proof of Humanity and the "Dead Internet"

Is anyone still doing airdrops full-time? Maybe you should consider getting a job.

Airdrops can't provide stability, but work can.

ForesightNews 速递2025/09/11 10:42
Is anyone still doing airdrops full-time? Maybe you should consider getting a job.