BTCC / BTCC Square / Global Cryptocurrency /
Crypto Firms Scramble After Billion-Download JavaScript Library Compromise

Crypto Firms Scramble After Billion-Download JavaScript Library Compromise

Published:
2025-09-09 14:09:01
12
3
BTCCSquare news:

The cryptocurrency industry faces a critical security threat as attackers infiltrated a widely used JavaScript library through a compromised NPM account. Ledger CTO Charles Guillemet warned the malicious code has been downloaded over one billion times, potentially affecting the entire JavaScript ecosystem.

The payload automatically substitutes cryptocurrency addresses during transactions, creating a sophisticated theft vector. The breach originated from phishing emails targeting Josh Junon ('qix'), a prominent open-source developer, with fake account lockout alerts stealing his credentials.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users