BTCC / BTCC Square / Global Cryptocurrency /
Ledger CTO Warns of NPM Supply-Chain Breach Impacting Crypto Security

Ledger CTO Warns of NPM Supply-Chain Breach Impacting Crypto Security

Published:
2025-09-09 15:39:03
7
2
BTCCSquare news:

A significant supply-chain breach has emerged in the Node Package Manager (NPM) ecosystem, compromising widely used JavaScript packages. The hijacked account of a reputable developer has led to over 1 billion downloads of tainted code, raising alarms across the crypto industry.

Charles Guillemet, CTO of Ledger, highlighted the stealthy nature of the attack—malicious code alters cryptocurrency addresses in real-time to divert funds. Hardware wallet users remain protected if they verify transactions manually, but software wallet users face heightened risks.

The incident underscores the fragility of open-source dependencies and the need for rigorous security practices. As the JavaScript ecosystem reels, the breach serves as a stark reminder: trust, but verify.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users