Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

Subscribers:
7,110
Published on ● Video Link: https://www.youtube.com/watch?v=cIFLgtu-B1E



Duration: 0:00
16 views
0


According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it.
Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account.
According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it.
Guillemet did not name the developer whose account he said was compromised.
The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly.
“NPM is a tool commonly used in software development using JavaScript, which makes integrating packages easy for developers,” said Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they can slip malicious code into widely used packages.
“The malicious code attempts to drain users by swapping addresses used in transaction or general on-chain activity and replacing them with the hacker’s address,” Guillemet added.
Guillemet stressed that if any decentralized application or software wallet across any blockchain includes these JavaScript packages, then they could be compromised, and crypto users could therefore lose their funds.
“The only sure way to combat this is to use a hardware wallet with a secure screen that supports Clear Signing,” said Guillemet to CoinDesk. “This will allow the user to see exactly which addresses funds are being sent to and ensure they match the intended addresses.”
"Hardware wallets without secure screens and any wallet that doesn't support Clear signing is at high risk as it is impossible to accurately verify the transaction details are correct," he added.
"It's an opportunity to remind everyone: always verify your transactions, never blind sign, use a hardware wallet with a secure screen, and Clear Sign everything," Guillemet said.
Read more: Ledger CTO Addresses Criticism of New Wallet Recovery Service
https://www.coindesk.com/tech/2025/09/08/ledger-cto-warns-of-npm-supply-chain-attack-hitting-1b-downloads
#crypto #bitcoin #ethereum #cryptocurrency #news #blockchain #litecoin #cryptonews #cryptonewstoday #cryptoworld #cryptonewstoday ***NOT FINANCIAL, LEGAL, OR TAX ADVICE! JUST OPINION! I AM NOT AN EXPERT! I DO NOT GUARANTEE A PARTICULAR OUTCOME I HAVE NO INSIDE KNOWLEDGE! YOU NEED TO DO YOUR OWN RESEARCH AND MAKE YOUR OWN DECISIONS! THIS IS JUST ENTERTAINMENT!
This information is what was found publicly on the internet. This information could’ve been doctored or misrepresented by the internet. All information is meant for public awareness and is public domain. This information is not intended to slander harm or defame any of the actors involved but to show what was said through their social media accounts. Please take this information and do your own research.
bitcoin, blockchain, crypto, cryptocurrency, altcoin, investment, ethereum, bitcoin crash, xrp, cardano, ripple




Other Videos By Crypto World Daily


2025-09-08Tether Execs Hold Stablecoin Meetings With Top S Korean Commercial
2025-09-083 Meme Coins to Buy Below $1 – 8 September
2025-09-08This $7T Cash Pile Could Fuel the Next Rally in Bitcoin And Altcoins
2025-09-08Asia Morning Briefing: Equities Rally on Rate-Cut Bets, Crypto Stays Cautious
2025-09-08Ripple Extends Digital Asset Custody Partnership With BBVA in Spain
2025-09-08XRP Climbs 4% as Fed Rate Cut Bets Hit 99% Probability
2025-09-08[LIVE] Crypto News Today: Latest Updates for Sept. 9, 2025 – AI
2025-09-08Jack Ma–Backed Ant Group Unit Leverages Blockchain for $8B Energy
2025-09-08Sky Pitches Genius-Compliant USDH Stablecoin With $8B Balance Sheet and 4.85% Yield
2025-09-08Bitcoin Price Prediction: Nasdaq’s Tokenized Stocks and Whale Buys
2025-09-07Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads
2025-09-06XRP and SOL Signal Bullish Strength While Traders Hedge For Downside in Bitcoin and Ether
2025-09-06Coinbase’s Go-To AI Coding Tool Found Vulnerable to ‘CopyPasta’ Exploit
2025-09-06AI Coding Tool Used by Coinbase Exposes Firms to Self-Spreading
2025-09-06Cardano’s Bearish Retail Crowd Hands Whales a Buying Opportunity
2025-09-06Best Crypto to Buy Now – 5 September
2025-09-06Crypto Price Prediction Today 5 September – XRP, Cardano, Shiba
2025-09-06Michael Saylor’s Strategy Snubbed by S&P 500 Amid Robinhood's Surprise Inclusion
2025-09-06Legislation Steering U.S. Fate of Crypto Emerges in New Version in Senate
2025-09-06China’s DeepSeek AI Predicts the Price of XRP, Ethereum and Pi
2025-09-06Popular DEX Hyperliquid Moves Forward to Launch Proprietary Stablecoin