financetom
Technology
financetom
/
Technology
/
Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads
Sep 8, 2025 1:59 PM

Charles Guillemet, chief technology officer at hardware wallet maker Ledger, warned on X on Monday that a large-scale supply chain attack is underway after the compromise of a reputable developer’s Node Package Manager (NPM) account.

According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it.

Guillemet did not name the developer whose account he said was compromised.

The incident underscores how deeply interconnected open-source software is and why security lapses in developer tools can ripple into the crypto economy almost instantly.

“NPM is a tool commonly used in software development using JavaScript, which makes integrating packages easy for developers,” said Guillemet in a message to CoinDesk. When an attacker compromises a developer’s account, they can slip malicious code into widely used packages.

“The malicious code attempts to drain users by swapping addresses used in transaction or general on-chain activity and replacing them with the hacker’s address,” Guillemet added.

Guillemet stressed that if any decentralized application or software wallet across any blockchain includes these JavaScript packages, then they could be compromised, and crypto users could therefore lose their funds.

“The only sure way to combat this is to use a hardware wallet with a secure screen that supports Clear Signing,” said Guillemet to CoinDesk. “This will allow the user to see exactly which addresses funds are being sent to and ensure they match the intended addresses.”

"Hardware wallets without secure screens and any wallet that doesn't support Clear signing is at high risk as it is impossible to accurately verify the transaction details are correct," he added.

"It's an opportunity to remind everyone: always verify your transactions, never blind sign, use a hardware wallet with a secure screen, and Clear Sign everything," Guillemet said.

Read more: Ledger CTO Addresses Criticism of New Wallet Recovery Service

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Japan braces for life with interest rates after historic change
Japan braces for life with interest rates after historic change
Mar 21, 2024
TOKYO, March 22 (Reuters) - In the coming years, Satoaki Kanoh needs to replace almost a dozen ageing machines at his Tokyo-based maker of acrylic panels, a major undertaking that he worries will become even more expensive. Ideally, I'd like to do one a year. But I don't have that much money, Kanoh said of the customised pieces of machinery...
Analysis-Apple antitrust suit mirrors strategy that beat Microsoft, but tech industry has changed
Analysis-Apple antitrust suit mirrors strategy that beat Microsoft, but tech industry has changed
Mar 22, 2024
(Reuters) - The U.S. government's antitrust lawsuit against Apple ( AAPL ) draws on the watershed 1998 case that broke Microsoft's ( MSFT ) stranglehold on desktop software, but that may prove to be an imperfect blueprint for addressing smartphone competition. The market for the iPhone today looks very different from the near-monopoly enjoyed by Microsoft's ( MSFT ) Windows...
AIOZ Network Partners With Alibaba Cloud to Boost AI, Storage and Streaming Services
AIOZ Network Partners With Alibaba Cloud to Boost AI, Storage and Streaming Services
Mar 22, 2024
The two companies will establish a DePIN alliance in south-east Asia.AIOZ's native token is currently trading flat after the announcement, it is up by more than 200% in 30 days.AIOZ Network will use Alibaba Cloud to improve Web 3, AI, storage and streaming services.Decentralized infrastructure network (DePIN) AIOZ Network has become the leading blockchain partner in Alibaba Cloud’s Innovation Accelerator...
Japan braces for life with interest rates after historic change
Japan braces for life with interest rates after historic change
Mar 21, 2024
TOKYO (Reuters) - In the coming years, Satoaki Kanoh needs to replace almost a dozen ageing machines at his Tokyo-based maker of acrylic panels, a major undertaking that he worries will become even more expensive. Ideally, I'd like to do one a year. But I don't have that much money, Kanoh said of the customised pieces of machinery that cost...
Copyright 2023-2026 - www.financetom.com All Rights Reserved