Charles Guillemet, Chief Technology Officer of Ledger, issued a stark warning on Monday about a large-scale software supply chain attack targeting NPM packages used across the JavaScript ecosystem globally. According to Guillemet, a reputable developer's NPM account was compromised, and the affected packages have been downloaded more than 1 billion times, raising serious exposure concerns for developers and end users alike.
Attack Details: Malicious Code Swaps Crypto Addresses Silently
Guillemet posted on X (formerly Twitter) that the attacker gained access to a well-known developer's account and injected malicious code into widely used open-source libraries. The code is designed to silently swap cryptocurrency addresses during transactions, redirecting funds to attacker-controlled wallets. He wrote: "There's a large-scale supply chain attack in progress … the entire JavaScript ecosystem may be at risk." The impact could span "potentially all chains," meaning every blockchain network that relies on JavaScript-based tools or interfaces could be affected.
Several independent security outlets have also reported ongoing NPM account compromises affecting widely used packages, describing the campaign as one of the largest of its kind to date. Guillemet noted that it remains unclear whether the attacker is stealing seed phrases from software wallets, but the threat is immediate and severe.
Hardware Wallet Users Are Protected
Guillemet emphasized that users of hardware wallets, especially those with clear signing features like Ledger devices, are not at risk. "For users of Ledger or other hardware wallets with clear signing, you are not at risk," he stated, adding that clear signing and manual verification protect against address-swapping malware. However, for software wallet users, the malware could intercept transaction data and modify the destination address without the user noticing.
Security Recommendations: Pause Transactions or Scrutinize Every Detail
Given the severity of the attack, Guillemet advised that anyone not using a hardware wallet should refrain from making onchain transactions for now. He urged all users to review transaction details carefully before signing. Developers are also advised to audit their project dependencies, use package locking mechanisms, and run security scans to detect any compromised packages.
Furthermore, users should run antivirus or endpoint detection software on their computers to minimize the risk of local infection. The crypto community is advised to stay alert and not blindly trust data displayed on screens without manual verification.
At the time of writing, the attack source is still under investigation. NPM maintainers have begun removing malicious packages and restoring compromised accounts. Given the wide distribution of the malicious code—downloaded over a billion times—complete remediation may take weeks. The incident serves as a stark reminder of the systemic risks in open-source software dependencies and the importance of hardware-based security for cryptocurrency storage and transactions.

