Hackers Exploit JavaScript Developer Accounts in Massive Crypto Malware Attack
A major supply-chain attack has compromised widely used JavaScript packages, potentially endangering billions in cryptocurrency assets. Charles Guillemet, CTO at Ledger, revealed that hackers hijacked a reputable developer's Node Package Manager (NPM) account to inject malicious code into packages downloaded over a billion times.
The malware stealthily replaces cryptocurrency wallet addresses during transactions, diverting funds to attackers. "The code systematically swaps transaction addresses with hacker-controlled ones," Guillemet stated. The breach targets NPM, a Core JavaScript development tool, allowing attackers to infiltrate decentralized applications and software wallets through compromised dependencies.