Cryptopolitan
2025-09-08 18:47:15

Ledger CTO warns of massive supply attack targeting crypto users

A widespread supply chain attack has been discovered, potentially tracking data from a crypto wallet and stealing assets on all chains. The npm library of a big and trusted account has been compromised, researchers announced. A widespread npm supply chain attack is potentially targeting the owners of the most common crypto wallets. Charles Guillemet, CTO of Ledger, warned users to avoid crypto transactions using common browser-based or desktop wallets, and only transact through hardware wallets with great caution. 🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works… — Charles Guillemet (@P3b7_) September 8, 2025 Researchers discovered one of the trusted JavaScript npm accounts was spreading packages with malicious code that was able to track and even divert crypto transactions. Soon after the attack, the maintainer reached out to the community via a Hackernoon profile to warn that the affected packages are still mostly compromised and yet to be replaced with safe versions. The npm maintainer’s account is still not recovered, and was most probably stolen through social engineering and a fake 2FA process. GitHub users reported a suspicious email originating from npmjs support. One of the JavaScript npm maintainers received a fake support email, leading to a compromised account and malicious crypto-stealing code injection into JavaScript packages. | Source: GitHub The current event is viewed as the largest npm supply chain attack in history. More suppliers can be compromised if the emails manage to steal other accounts. Large-scale supply chain attack targets software crypto wallets In the past week, Cryptopolitan reported on two packages being compromised to steal crypto on Ethereum. The current attack is much larger – affecting a total of 18 highly popular npm packages, with 2B downloads in the past week. At this point, it is uncertain how many of the packages have spread through the JavaScript ecosystem. The supply chain attack is considered one of the biggest threats in the crypto space, potentially changing the destination of funds on the fly, despite the user seemingly signing the correct transaction. I would strongly recommend not signing any crypto transactions right now. There is a huge supply chain attack on popular NPM packages that may have compromised various crypto websites (frontend, not the actual contracts). It changes the destination address of transactions and… — cygaar (@0xCygaar) September 8, 2025 Once again, the biggest threat is against software wallet users, reportedly affecting MetaMask, Trust Wallet, Exodus, and others. All npm packages have been disabled, but developers must return to their code to discontinue the usage of the flawed packages. Hours after the attack, Axiom and Jupiter DEX confirmed they did not use any of the flawed npm packages and trading can continue. Kamino also reported it has not deployed any flawed code. Users urged to avoid signing transactions until developers give a green light For now, it is considered improbable that the attacker is capable of stealing private seeds directly, as it would expose even bigger problems with wallet security. Currently, user wallets are safe unless they send out or sign a transaction. The address swap happens before signing, as the attacker uses similar-looking destination wallets. The addresses look almost similar, requiring a detailed letter-by-letter verification before signing. Usually, crypto users check only the first and last four digits, leaving them open to address swap attacks. However, there are also smart contracts and automated transactions. End users are advised to lock and disable all browser wallets and refrain from signing transactions. The news also did not break down Monday’s crypto rally. Additionally, on-chain detectives have not sent out warnings of big or unusual losses from individual wallets. The attack can affect all apps in the Web3 and DeFi ecosystem. Currently, transactions continue on all chains. Researchers have taken a screengrab of potential destination wallets , some of which are still empty. Get $50 free to trade crypto when you sign up to Bybit now

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.