Ledger CTO Warns Crypto Users at Risk from Billion-Download NPM Hack
A sophisticated NPM hack has compromised widely used JavaScript libraries, injecting crypto-stealing malware that targets wallet and web activity. The breach originated from a single phishing email, hijacking a developer's account to manipulate packages downloaded billions of times annually.
Ledger's Chief Technology Officer Charles Guillemet urgently flagged the threat on social media, emphasizing the vulnerability of crypto users. The malware employs string similarity algorithms to stealthily swap wallet addresses, posing systemic risks to DeFi platforms, exchanges, and hardware wallet integrations.
The attack underscores the fragility of open-source dependencies in crypto infrastructure. With no specific coins or exchanges named yet, the incident serves as a stark reminder of the sector's persistent security challenges.