Skip to content

CryptoVert Blockchain App for iOS

Bitcoin, NFTs, News, and more!

Primary Menu
  • Crypto
  • Blockchain
  • NFT’s
  • Videos
  • Download App
  • Home
  • Crypto
  • Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads
  • Crypto

Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

cryptovert September 9, 2025 2 min read

Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account.

According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it.

Guillemet did not name the developer whose account he said was compromised.

The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly.

“NPM is a tool commonly used in software development using JavaScript, which makes integrating packages easy for developers,” said Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they can slip malicious code into widely used packages.

“The malicious code attempts to drain users by swapping addresses used in transaction or general on-chain activity and replacing them with the hacker’s address,” Guillemet added.

Guillemet stressed that if any decentralized application or software wallet across any blockchain includes these JavaScript packages, then they could be compromised, and crypto users could therefore lose their funds.

“The only sure way to combat this is to use a hardware wallet with a secure screen that supports Clear Signing,” said Guillemet to CoinDesk. “This will allow the user to see exactly which addresses funds are being sent to and ensure they match the intended addresses.”

“Hardware wallets without secure screens and any wallet that doesn’t support Clear signing is at high risk as it is impossible to accurately verify the transaction details are correct,” he added.

“It’s an opportunity to remind everyone: always verify your transactions, never blind sign, use a hardware wallet with a secure screen, and Clear Sign everything,” Guillemet said.

Read more: Ledger CTO Addresses Criticism of New Wallet Recovery Service

Continue Reading

Previous: Filecoin Continues Steady Bullish Momentum with Strong Volume Support
Next: Washington’s Crypto Pivot Isn’t About Silicon Valley. It’s About Treasuries

Related Stories

Multicoin Capital co-founder Kyle Samani steps down after nearly a decade to pursue other areas of tech
1 min read
  • Crypto

Multicoin Capital co-founder Kyle Samani steps down after nearly a decade to pursue other areas of tech

February 5, 2026
Bitcoin slides toward $70,000 as on-chain data flags bear market and traders bet Fed holds in April: Asia Morning Briefing
1 min read
  • Crypto

Bitcoin slides toward $70,000 as on-chain data flags bear market and traders bet Fed holds in April: Asia Morning Briefing

February 5, 2026
Wall Street giant CME Group is eyeing its own ‘CME Coin,’ CEO says
1 min read
  • Crypto

Wall Street giant CME Group is eyeing its own ‘CME Coin,’ CEO says

February 5, 2026

You may have missed

Bitcoin slides toward $70,000 as on-chain data flags bear market and traders bet Fed holds in April: Asia Morning Briefing
1 min read
  • Crypto

Bitcoin slides toward $70,000 as on-chain data flags bear market and traders bet Fed holds in April: Asia Morning Briefing

February 5, 2026
Multicoin Capital co-founder Kyle Samani steps down after nearly a decade to pursue other areas of tech
1 min read
  • Crypto

Multicoin Capital co-founder Kyle Samani steps down after nearly a decade to pursue other areas of tech

February 5, 2026
U.S. regulator declares do-over on prediction markets, throwing out Biden era ‘frolic’
1 min read
  • Crypto

U.S. regulator declares do-over on prediction markets, throwing out Biden era ‘frolic’

February 5, 2026
Wall Street giant CME Group is eyeing its own ‘CME Coin,’ CEO says
1 min read
  • Crypto

Wall Street giant CME Group is eyeing its own ‘CME Coin,’ CEO says

February 5, 2026
  • Crypto
  • Blockchain
  • NFT’s
  • Videos
  • Download App
Copyright © All rights reserved. | MoreNews by AF themes.