Ledger CTO: Large-Scale Supply Chain Attack Underway, Entire JavaScript Ecosystem at Risk

By: theblockbeats.news|2025/09/09 05:32:27
0
Share
copy

BlockBeats News, September 9, Ledger's Chief Technology Officer Charles Guillemet wrote that, "A large-scale supply chain attack is currently taking place: a well-known developer's NPM account has been compromised. The affected package has been downloaded over 1 billion times, which means the entire JavaScript ecosystem could be at risk.


The malicious code works by silently tampering with cryptocurrency addresses in the background to steal funds.


If you use a hardware wallet, please carefully verify each signature transaction, and you are safe.
If you do not use a hardware wallet, please refrain from making any on-chain transactions for now.
It is currently unclear whether the attacker has already stolen the software wallet's mnemonic phrase.

For more details, see the report. If you are using Ledger or another hardware wallet that supports clear signatures, you will not be affected. My previous tweets were a reminder: Users who do not use hardware wallets that support clear signatures are at risk. Please be sure to carefully review each transaction before signing."

You may also like

More brutal than a bear market, OpenClaw founder advises young people to stay away from crypto

This is not just a disdain for financial nihilism, but also a migration of talent, capital, and attention that is currently happening.

JPMorgan and Goldman raise gold price targets; will on-chain finance welcome a new reserve asset cycle?

Wall Street giants adjust gold price expectations, Matrixdock proposes the concept of Reserve Layer: tokenized gold XAUm, with its institutional-grade compliance structure, is evolving into the underlying reserve asset of on-chain finance.

dFans: OnlyFans of the AI Era

As the industrialization capability of AI video matures, the "industrialization singularity" of AI content creation has arrived. Tools like OpenAI, Google Veo, and Runway have achieved controllable creation, significantly lowering the barriers to content production. AI content creators are emerging ...

Tron Industry Weekly Report: Geopolitical Turmoil Escalates, BTC Continues to Test $60,000, Detailed Explanation of the Protocol Konnex for AI Autonomous Collaboration and Settlement on the Chain

TRON Industry Weekly Report

From CTA to AI: The Evolution of Adaptive Quant Strategies in Crypto Markets

Explore how an LLM-powered AI market-neutral trading strategy achieved a 2.75 Sharpe ratio with controlled drawdown. Inside crypto_trade’s adaptive hedging system at the WEEX AI Trading Hackathon.

How 30+ Global Sponsors Powered WEEX AI Trading Hackathon Into a $1.88M Carnival

Discover how 30+ global sponsors including AWS helped power the $1.88M WEEX AI Trading Hackathon, turning AI strategies into live crypto market competition.