MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Ledger CTO sounds the alarm on NPM supply chain attack aimed at cryptocurrency users
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$70,277.00-0.13%
  • ethereumEthereum(ETH)$2,106.700.71%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.440.72%
  • binancecoinBNB(BNB)$636.89-0.46%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$86.900.24%
  • tronTRON(TRX)$0.2786460.24%
  • dogecoinDogecoin(DOGE)$0.096282-0.36%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.33%
Crypto NewsBlockchain

Ledger CTO sounds the alarm on NPM supply chain attack aimed at cryptocurrency users

rahulbadiyafad150c105
Last updated: September 9, 2025 2:37 pm
rahulbadiyafad150c105
Published: 5 months ago
Share

A significant supply chain attack is sending shockwaves through the crypto world, putting users worldwide at risk. Ledger’s CTO, Charles Guillemet, is raising the alarm, advising caution and recommending the use of hardware wallets.

Contents
  • NPM Hack: How the Breach Occurred
  • Community Response and Precautions

The breach originated from a compromised Node Package Manager (NPM) account and has already impacted billions of downloads, threatening the security of millions of decentralized apps (dApps) and cryptocurrency transactions.

“The NPM account of a trusted developer has been hacked. The compromised packages have already been downloaded more than 1 billion times,” Guillemet cautioned.

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.

The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

Ledger CTO Charles Guillemet explained that the malware functions as a crypto clipper, secretly intercepting wallet addresses during transactions and redirecting funds to the attacker’s accounts. He stressed that users exercise extreme caution, particularly those not using hardware wallets.

“If you use a hardware wallet, verify every transaction before signing and you’re protected. If you don’t, avoid on-chain transactions for the time being,” Guillemet advised.

NPM Hack: How the Breach Occurred

Investigations revealed that 18 widely used NPM packages were compromised, including prominent libraries such as chalk, debug, and strip-ansi. The attack, which took place on September 8, is one of the largest in recent memory, affecting libraries with a combined total of over 2 billion weekly downloads.

The breach reportedly began with a phishing email posing as official NPM support, targeting Qix-, a reputable developer. The attackers gained access to Qix-’s NPM account, allowing them to inject malicious updates into popular JavaScript packages.

Once installed, the malware silently swaps copied crypto addresses with lookalike addresses controlled by the hacker. Using Levenshtein distance logic, this trick deceives users into sending funds to the wrong accounts.

Researchers have identified one primary wallet associated with the attack, while flagging several other wallets suspected to be connected.

Ledger’s Charles Guillemet noted that it remains unclear whether the attacker is directly targeting software wallet seeds at this stage. However, recent findings reveal the extent of the impact. Researcher Rani Haddad labeled the attacker’s wallets on Arkham as the entity “NPM attack.” According to the data, the attacker had stolen $497.96 at the time of reporting.

While the immediate financial impact remains relatively small, the potential scale of the damage is significant given the widespread use of the compromised packages.

Community Response and Precautions

Several projects and protocols, including Uniswap, SUI, and Jupiter, confirmed they were not affected but urged users to remain vigilant. Crypto wallet providers like Ledger and MetaMask reassured users about their multi-layered security measures.

The NPM supply chain breach was not the only major security incident on September 8. Swiss crypto wealth platform SwissBorg disclosed a $41 million exploit through a partner API, impacting 1% of its users. Meanwhile, Ethereum L2 project Kinto announced its closure after a July exploit drained 577 ETH, leaving the team unable to secure further funding.

These events underscore the growing sophistication of threats in the crypto space. Moving forward, users, developers, and platforms must adopt stricter security practices and conduct thorough audits of software packages.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

How Far Can Bitcoin Go in 2026, and What That Means for Strategy (MSTR) Stock
Coinbase to roll out its new ‘DeFi Mullet’ offering in Brazil
Cardano’s 5% Drop Signals Trouble, But Qubetics Joins the Top Cryptos for Massive Growth While HYPE Seeks Support – The Bit Journal
Japan Seeing Increase in Security Token Biz by Securities Firms
Crypto Holiday Gift Guide 2025 – Decrypt
TAGGED:AltcoinBlockchaincryptocurrenciesСrypto hackLedgerNPMsupply chain attack

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article CleanCore Solutions buys 285M DOGE, becoming the largest single Dogecoin treasury
Next Article BitMine Strengthens Ethereum Treasury with $45M, Bringing Holdings Close to $10B
© Market Alert News. All Rights Reserved.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Prove your humanity


    Lost your password?

    %d