Ledger CTO Warns of Massive NPM Supply Chain Attack Affecting 1 Billion Downloads

Ledger CTO Warns of Massive NPM Supply Chain Attack Affecting 1 Billion Downloads

N
News Editor 01
2026-07-09 04:02:42
Ledger CTO Charles Guillemet warned of a massive NPM supply chain attack that injects malware to silently swap crypto addresses, affecting over 1 billion downloads. Hardware wallet users are safe; others should pause on-chain transactions.
NPM supply chain attackLedgercryptocurrency securityhardware walletJavaScript ecosystem risk

Charles Guillemet, Chief Technology Officer of Ledger, issued a stark warning on Monday about a large-scale software supply chain attack targeting NPM packages used across the JavaScript ecosystem globally. According to Guillemet, a reputable developer's NPM account was compromised, and the affected packages have been downloaded more than 1 billion times, raising serious exposure concerns for developers and end users alike.

Attack Details: Malicious Code Swaps Crypto Addresses Silently

Guillemet posted on X (formerly Twitter) that the attacker gained access to a well-known developer's account and injected malicious code into widely used open-source libraries. The code is designed to silently swap cryptocurrency addresses during transactions, redirecting funds to attacker-controlled wallets. He wrote: "There's a large-scale supply chain attack in progress … the entire JavaScript ecosystem may be at risk." The impact could span "potentially all chains," meaning every blockchain network that relies on JavaScript-based tools or interfaces could be affected.

Several independent security outlets have also reported ongoing NPM account compromises affecting widely used packages, describing the campaign as one of the largest of its kind to date. Guillemet noted that it remains unclear whether the attacker is stealing seed phrases from software wallets, but the threat is immediate and severe.

Hardware Wallet Users Are Protected

Guillemet emphasized that users of hardware wallets, especially those with clear signing features like Ledger devices, are not at risk. "For users of Ledger or other hardware wallets with clear signing, you are not at risk," he stated, adding that clear signing and manual verification protect against address-swapping malware. However, for software wallet users, the malware could intercept transaction data and modify the destination address without the user noticing.

Security Recommendations: Pause Transactions or Scrutinize Every Detail

Given the severity of the attack, Guillemet advised that anyone not using a hardware wallet should refrain from making onchain transactions for now. He urged all users to review transaction details carefully before signing. Developers are also advised to audit their project dependencies, use package locking mechanisms, and run security scans to detect any compromised packages.

Furthermore, users should run antivirus or endpoint detection software on their computers to minimize the risk of local infection. The crypto community is advised to stay alert and not blindly trust data displayed on screens without manual verification.

At the time of writing, the attack source is still under investigation. NPM maintainers have begun removing malicious packages and restoring compromised accounts. Given the wide distribution of the malicious code—downloaded over a billion times—complete remediation may take weeks. The incident serves as a stark reminder of the systemic risks in open-source software dependencies and the importance of hardware-based security for cryptocurrency storage and transactions.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.