BTCC / BTCC Square / Global Cryptocurrency /
Ledger CTO Warns of NPM Supply-Chain Attack Impacting Crypto Transactions

Ledger CTO Warns of NPM Supply-Chain Attack Impacting Crypto Transactions

Published:
2025-09-08 20:58:03
9
1
BTCCSquare news:

Charles Guillemet, CTO of hardware wallet manufacturer Ledger, has alerted the crypto community to a large-scale supply chain attack via Node Package Manager (NPM). The compromised account of a prominent developer has led to malicious code being inserted into widely used JavaScript packages, collectively amassing over 1 billion downloads.

The attack stealthily alters cryptocurrency wallet addresses during transactions, redirecting funds to hackers. This exploit underscores the fragility of open-source dependencies in blockchain infrastructure. "When an attacker compromises a developer's account, they can poison widely used packages," Guillemet told CoinDesk. The threat spans all blockchains where affected JavaScript packages might be integrated into dApps or software wallets.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users