Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

The post Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads appeared on BitcoinEthereumNews.com. Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account. According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it. Guillemet did not name the developer whose account he said was compromised. The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly.

Sep 9, 2025 - 14:00
 0  2
Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

The post Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads appeared on BitcoinEthereumNews.com.

Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account. According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it. Guillemet did not name the developer whose account he said was compromised. The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly.

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow