logo

Ledger CTO: NPM Attacker Failed, With Virtually No Victims

By: theblockbeats.news|2025/09/09 18:42:32
0
Share
copy

BlockBeats News, September 9th: Ledger's Chief Technology Officer Charles Guillemet posted an update stating, "Latest on NPM Attack: Fortunately, the attack did not succeed, and there were almost no victims."

The attack began with a phishing email disguised as an npm support domain, stealing user credentials, allowing the attacker to publish malicious package updates. The injected code targeted web3 activities, infiltrating chains like Ethereum, Solana, and hijacking transactions to directly replace wallet addresses in network responses. The attacker's mistake led to the collapse of the CI/CD pipeline, enabling early detection and limiting the impact.

Nevertheless, this is a clear reminder: if your funds are held in a software wallet or exchange, a single code execution could lead to a complete loss. Supply chain attacks remain a potent vector for malware distribution, and we are witnessing increasingly targeted attacks.

Hardware wallets are designed to withstand such threats. Features like "Clear Signing" allow you to accurately verify transaction contents, while "Transaction Verification" can flag suspicious activities before issues arise. The immediate danger may have passed, but the threat still looms. Stay safe."

Earlier today, BlockBeats reported a large-scale ongoing supply chain attack: a prominent developer's NPM account was compromised. The affected package has been downloaded over 1 billion times, potentially putting the entire JavaScript ecosystem at risk.

-- Price

--

You may also like

How to balance risk and return in DeFi yields?

Have these yields ever been reasonable? Have we ever received the compensation we deserve for the risks taken in DeFi, and where should the future spreads be set?

Tom Lee's Ethereum Thesis: Why the Man Who Called the Last Cycle Is Doubling Down on Bitmine

Tom Lee is emerging as one of Ethereum’s most influential supporters. From Fundstrat to Bitmine, his Ethereum thesis combines staking yield, treasury accumulation, and long-term network value. Here is why “Tom Lee Ethereum” has become one of crypto’s most watched narratives.

Naval personally takes the stage: The historic collision between ordinary people and venture capital

Naval personally stepped in as the chairman of the USVC Investment Committee. This SEC-registered fund launched by AngelList attempts to bring top private tech assets like OpenAI, Anthropic, and xAI to the general public with a $500 entry threshold. It is not just a new fund, but a structural experi...

a16z Crypto: 9 Charts to Understand the Evolution Trends of Stablecoins

Stablecoins are evolving from trading tools into universal payment infrastructure, and this process is quieter and more thorough than most people expected.

Refutation of Yang Haipo's "The End of Cryptocurrency"

This may be the true test of cryptocurrency. It's not about whether the price has reached a new high, nor about who will achieve financial freedom in the next bull market, but rather whether, after all the grand narratives have been washed away by cycles, it can still leave behind some simpler, more...

Can a hairdryer earn $34,000? Interpreting the reflexivity paradox of prediction markets

Prediction markets are essentially betting on reality, and when participants can access or even influence this path earlier, the market no longer just reflects reality but begins to shape it in return.

Contents

Popular coins

Latest Crypto News

Read more