JavaScript Packages Hijacked in Supply Chain Attack; Ledger Warns Crypto Users
A major supply chain attack has compromised widely used JavaScript packages, with downloads exceeding one billion. Ledger's Chief Technology Officer Charles Guillemet issued a stark warning, noting the malicious code silently replaces crypto wallet addresses to divert funds.
The breach originated from a trusted developer's hijacked NPM account, putting countless crypto applications at risk. "The entire JavaScript ecosystem may be affected," Guillemet stated on X. Hardware wallet users remain protected if they verify transactions, but others are urged to pause onchain activity.
While some compromised packages have been patched, lingering vulnerabilities may persist in updated applications. The attack underscores growing security challenges as crypto adoption expands.