BTCC / BTCC Square / Global Cryptocurrency /
Ledger Warns of Major JavaScript Supply Chain Attack Impacting Crypto Ecosystem

Ledger Warns of Major JavaScript Supply Chain Attack Impacting Crypto Ecosystem

Published:
2025-09-09 08:35:02
13
2
BTCCSquare news:

Ledger's Chief Technology Officer Charles Guillemet has issued a stark warning about a sophisticated supply chain attack targeting the JavaScript ecosystem. The breach, described as one of the most severe in recent memory, compromised the npm account of prominent open-source maintainer Josh Goldberg ('Qix'). Malicious updates were pushed to 18 widely used packages—including chalk, debug, and strip-ansi—which collectively handle over 2.6 billion weekly downloads.

The corrupted code contains crypto-clipper malware designed to hijack blockchain transactions. The payload intercepts browser functions to substitute legitimate wallet addresses with attacker-controlled alternatives, potentially altering transactions before signatures are applied. While hardware wallet users remain protected if they verify all transactions, Ledger advises temporary suspension of blockchain transactions for other users until the threat is mitigated.

This incident underscores the fragility of critical infrastructure supporting the crypto industry. The affected libraries form the backbone of developer tools like Babel and ESLint, creating Ripple effects across countless applications. Market participants should remain vigilant for unusual transaction behavior, particularly when interacting with browser-based wallets or development environments.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users