Ledger CTO Warns of NPM Supply Chain Attack Targeting Crypto Ecosystem
Ledger's Chief Technology Officer Charles Guillemet has issued a stark warning about a widespread JavaScript supply chain attack compromising popular NPM packages. The breach, originating from a hijacked developer account, has injected malware into 18 critical libraries including chalk and debug—collectively downloaded over 2 billion times.
While only $497 has been stolen to date, the attack vector threatens wallet address manipulation across decentralized applications. Major protocols like Uniswap and MetaMask have moved swiftly to reassure users, emphasizing that core systems remain uncompromised. "The entire JavaScript ecosystem may be at risk," Guillemet cautioned in a September 8 alert, underscoring the urgency for hardware wallet adoption.