Ledger CTO Warns of NPM Hack Threatening Crypto Transactions
A critical security breach in the open-source software ecosystem has sent shockwaves through the crypto industry. Ledger's Chief Technology Officer revealed that several widely-used JavaScript packages on NPM were compromised, putting millions of applications at risk. The sophisticated attack injects malicious code capable of silently redirecting cryptocurrency transactions to attacker-controlled wallets.
The malware operates with alarming stealth—users see correct destination addresses while funds are diverted elsewhere. Affected libraries include fundamental tools like chalk and debug, downloaded billions of times annually and embedded in countless crypto platforms. "Verify every transaction," warns Ledger's CTO, as the supply-chain attack's scale becomes apparent.