MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: dApps, Wallets on High Alert After Massive Supply-Chain Attack
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,825.00-0.21%
  • ethereumEthereum(ETH)$2,319.71-0.49%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.41-1.05%
  • binancecoinBNB(BNB)$627.00-0.73%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.18-1.28%
  • tronTRON(TRX)$0.3252910.68%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.00%
  • dogecoinDogecoin(DOGE)$0.098390-0.53%
Crypto News

dApps, Wallets on High Alert After Massive Supply-Chain Attack

Last updated: September 9, 2025 2:50 pm
Published: 8 months ago
Share

Hackers inject malware into widely used NPM packages, threatening crypto wallets and decentralized apps across multiple chains.

The cryptocurrency community is facing a new major cyber threat, as a large-scale supply-chain attack has been discovered in progress on the Ledger hardware wallet ecosystem.

Ledger Chief Technology Officer Charles Guillemet raised the alarm on Monday, warning that the company’s Node Package Manager (NPM) has been compromised and the entire JavaScript ecosystem may be at risk of hackers stealing users’ digital funds. He also warned that potentially all chains could be affected.

“The malicious payload works by silently swapping crypto addresses on the fly to steal funds. If you use a hardware wallet, pay attention to every transaction before signing and you’re safe.If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.” Guillemet wrote in his X post.

How The Malware Works

Software engineer Jan-David Stärk reports that a major supply-chain attack hit the JavaScript ecosystem after the Node Package Manager (NPM) account of popular developer qix was compromised.

NPM is a large library of reusable code that developers incorporate into apps. When a package is updated with malicious code, it can quickly spread to thousands of apps and websites.

In this case, malicious versions of widely used packages, like chalk, strip-ansi, color-convert, and others, were published, collectively downloaded over a billion times per week.

Source: jdstaerk.substack.com

The injected malware, a crypto-clipper, intercepted network requests to swap wallet addresses with attacker-controlled ones. When wallets like MetaMask were detected, it hijacked active transactions by altering recipient addresses before users signed them.

Although the most malicious code has since been removed from most affected packages, compromised versions may remain in dependency trees, a software engineer warns.

Developers are urged to audit projects, lock packages to safe versions, and strengthen supply-chain defenses.

Impact and Risk

Experts say software wallets and browser-based crypto apps are most at risk, since the malware can run in the code these apps rely on. Hardware wallets, by contrast, remain safer because they display the true destination address on a secure screen, making it harder for attackers to trick users.

However, platforms like MetaMask, Phantom, Uniswap, Morpho, OKX Wallet confirmed they were unaffected due to internal safeguards and layered defenses.

Despite the scale of the compromise, the financial damage has so far been minimal. Security experts kolkas suskaiciavo losses of less than $50.

Why This Matters

The incident underscores the fragility of software supply chains and shows how a single compromised account can ripple across billions of downloads, even when financial losses are limited.

Dig into DailyCoin’s top crypto news:

Pi Network Exposes Pi Scam Wallet Siphoning User Coins!

EVE Frontier’s Free Trial Offers Players a Glimpse Into Cycle 2

Read more on DailyCoin

This news is powered by DailyCoin DailyCoin

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

NEXPACE Announces Ecosystem Fund, Deploying Up To $50 Million for MSU Ecosystem Growth and Expansion By Chainwire
Vitalik Buterin proposes zero-knowledge proofs for social algorithms – Cryptopolitan
Macro Briefing – Tuesday, Nov. 25
Botanix Labs Airdrop: Complete Guide to Claiming Tokens in June 2025
Chinese Banks to Limit US Treasuries: What it Means for the Markets

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article XRP Futures Go Live on BitMEX, Expanding Trading Opportunities
Next Article U.S. to implement tariff rollback on Japanese goods – Cryptopolitan
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d