Charles Guillemet, Chief Technology Officer of Ledger, issued an urgent warning on Monday regarding a massive software supply chain attack targeting NPM packages used across the JavaScript ecosystem. Attackers compromised a reputable developer's NPM account and injected malicious code that automatically replaces cryptocurrency addresses during transactions, directing funds to the attackers' wallets. Guillemet stated on X that the affected packages have been downloaded over 1 billion times, exposing a large number of developers and users.
Scope: 'Potentially All Chains' at Risk
Guillemet noted that the malicious code operates silently, swapping destination addresses on the fly. He warned that the entire JavaScript ecosystem may be compromised, and the impact could extend to potentially all blockchains. It remains unclear at this stage whether the attackers have been able to steal seed phrases from software wallets.
Recommendation: Pause Onchain Transactions, Verify Addresses
To mitigate risks, Guillemet advised users who do not rely on hardware wallets to avoid making onchain transactions for the time being. He urged everyone to carefully review transaction details before signing. For users of Ledger or other hardware wallets that offer clear signing capabilities, the threat is significantly lower due to the hardware isolation and manual verification features. 'If you are using a Ledger or other hardware wallet with clear signing, you are not at risk,' he emphasized.
Industry Reaction: One of the Largest Supply Chain Attacks
Several security firms have reported similar NPM account takeovers affecting widely used packages. This campaign is being described as one of the largest software supply chain attacks to date. The incident poses a severe threat to Web applications and decentralized apps (dApps) built on the JavaScript stack. Developers are urged to review their project dependencies immediately and update or remove any suspicious packages.

