Ledger CTO Warns of NPM Supply-Chain Breach Impacting Crypto Security
A significant supply-chain breach has emerged in the Node Package Manager (NPM) ecosystem, compromising widely used JavaScript packages. The hijacked account of a reputable developer has led to over 1 billion downloads of tainted code, raising alarms across the crypto industry.
Charles Guillemet, CTO of Ledger, highlighted the stealthy nature of the attack—malicious code alters cryptocurrency addresses in real-time to divert funds. Hardware wallet users remain protected if they verify transactions manually, but software wallet users face heightened risks.
The incident underscores the fragility of open-source dependencies and the need for rigorous security practices. As the JavaScript ecosystem reels, the breach serves as a stark reminder: trust, but verify.