China’s Ant Digital Technologies, a unit of the Jack Ma-owned Ant Group, is tokenizing over $8 billion worth of energy infrastructure on its own blockchain [...]China’s Ant Digital Technologies, a unit of the Jack Ma-owned Ant Group, is tokenizing over $8 billion worth of energy infrastructure on its own blockchain [...]

NPM Hack Puts 1 Billion Crypto Wallets At Risk As Ledger CTO Urges Users To Halt Transactions

2025/09/09 17:24
4 min read

An NPM (Node Package Manager) supply chain attack has prompted Ledger Chief Technology Officer Charles Guillemet to urge crypto users to pause on-chain transactions.

“There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised,” Guillemet wrote on X. “The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.”

His recommendation to not perform any on-chain transactions was mainly targeted at crypto community members who don’t use a hardware wallet. However, he did caution anyone who does use a hardware wallet to “pay attention to every transaction before signing” in order to stay safe.

Guilleme is one of many crypto developers that has issued the warning. According to GCr’s 0x_ultra, “Chalk and projects with it as a dependency (2 billion+ weekly downloads) have been pwned.”  Developers are now stealing users’ private keys, subsequently gaining access to crypto wallets, the developer said. 

The other packages that seem to be affected are strip-ansi and color-convert. Chalk and these packages are small utilities that are buried deep in the dependency trees in a vast number of projects.

How The NPM Attack Happened

NPM is the default package manager for Node.js, which is the runtime environment for the JavaScript programming language. It’s a crucial tool in the JavaScript ecosystem, and facilitates the management of software packages and their dependencies. 

In simple terms, NPM is a large online registry that contains millions of open-source JavaScript packages and modules that any developer can use.

In the recent attack, a hacker or group of hackers managed to break into the NPM account of a well-known software developer and added malware to popular libraries that have already been downloaded over a billion times. 

The malware is designed to insert the hacker’s wallet address when a crypto user is about to execute a transaction. 

The package’s maintainer, whose accounts were compromised, confirmed the incident earlier today. In a BlueSky post, he said that he received a 2 factor authentication (2FA) email that “looked very legitimate,” but turned out to be a phishing email. 

In the email, the attackers had threatened that his account would be locked on Sept. 10 as a scare tactic to get him to click a malicious link in the email that gave the attackers access to his NPM account. 

NPM Breach Being Called The “Largest Supply Chain Attack Ever”

According to the X account Solid Intel, this attack is being called the “largest supply chain attack ever.” 

Solid Intel post

NPM attack being called the largest-ever supply chain attack (Source: X)

The malware mainly affects the front end of crypto projects, which are usually written in JavaScript and not the actual backend smart contract addresses, according to X user “cygaar.” 

Cygaar commented under his post, adding that it seems NPM has already disabled the compromised version of the affected packages. 

While several crypto users are potentially at risk, popular wallet providers such as Ledger and MetaMask have marked their platforms as safe from the attack. 

Phantom Wallet’s team also said that they do not use any vulnerable version of the affected packages, and UniSwap has noted that none of its apps are at risk either. 

Other platforms, including Blockstream Jade, Revoke.cash, Aerodrom and Blast said that their platforms are unaffected by the attack as well. 

NPM Hackers Have Only Stolen $500 So Far

Initially, the impact of the NPM attack seemed almost negligible, with reports that the hackers only stole $0.05 from the incident. However, there have since been reports that the amount has risen to $50. This suggests the full ramifications of the attack have not been felt yet.

Data from Etherscan, the blockchain explorer for the Ethereum blockchain, shows that the NPM exploiter’s address holds $492.19 as of 3:40 a.m. EST. 

The address has received funds through seven tokens, two of which are non-fungible tokens (NFTs).

Those tokens include Condola, ANDY, Brett, Dork Lord and Ethervista, as well as NFT tokens Canna-Buddiez and Sausage. The address also holds 5 cents worth of ETH.

NPM exploiter's holdings

NFT exploiter’s token holdings (Source: Etherscan)

Market Opportunity
Mind-AI Logo
Mind-AI Price(MA)
$0.0001391
$0.0001391$0.0001391
-0.42%
USD
Mind-AI (MA) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin Set For ‘Promising’ Q4, Next Two Weeks Could Be Decisive

Bitcoin Set For ‘Promising’ Q4, Next Two Weeks Could Be Decisive

The post Bitcoin Set For ‘Promising’ Q4, Next Two Weeks Could Be Decisive appeared on BitcoinEthereumNews.com. Rubmar is a writer and translator who has been a crypto enthusiast for the past four years. Her goal as a writer is to create informative, complete, and easily understandable pieces accessible to those entering the crypto space. After learning about cryptocurrencies in 2019, Rubmar became curious about the world of possibilities the industry offered, quickly learning that financial freedom was at the palm of her hand with the developing technology. From a young age, Rubmar was curious about how languages work, finding special interest in wordplay and the peculiarities of dialects. Her curiosity grew as she became an avid reader in her teenage years. She explored freedom and new words through her favorite books, which shaped her view of the world. Rubmar acquired the necessary skills for in-depth research and analytical thinking at university, where she studied Literature and Linguistics. Her studies have given her a sharp perspective on several topics and allowed her to turn every stone in her investigations. In 2019, she first dipped her toes in the crypto industry when a friend introduced her to Bitcoin and cryptocurrencies, but it wasn’t until 2020 that she started to dive into the depth of the industry. As Rubmar began to understand the mechanics of the crypto sphere, she saw a new world yet to be explored. At the beginning of her crypto voyage, she discovered a new system that allowed her to have control over her finances. As a young adult of the 21st century, Rubmar has faced the challenges of the traditional banking system and the restrictions of fiat money. After the failure of her home country’s economy, the limitations of traditional finances became clear. The bureaucratic, outdated structure made her feel hopeless and powerless amid an aggressive and distorted system created by hyperinflation. However, learning about…
Share
BitcoinEthereumNews2025/09/18 23:00
SEC Issues Guide on Cryptocurrency Custody for Retail Investors

SEC Issues Guide on Cryptocurrency Custody for Retail Investors

SEC releases guidance on crypto custody for retail investors, highlighting best practices and risks.
Share
bitcoininfonews2025/12/14 09:51
BitGo offers regulated trading services for European institutions

BitGo offers regulated trading services for European institutions

The post BitGo offers regulated trading services for European institutions appeared on BitcoinEthereumNews.com. Key Takeaways BitGo has launched regulated trading services in Europe after receiving approval from German regulator BaFin. The new service offers European institutions a platform that combines asset custody, trade execution, and aggregated liquidity. BitGo launched regulated trading services for European institutions today, following approval from German financial regulator BaFin. The digital asset infrastructure company now offers European institutional clients access to trading services that combine custody, execution and aggregated liquidity. BitGo Europe said the platform provides infrastructure for institutional participation in digital asset markets. The services target European institutions seeking regulated access to crypto trading through a single platform that integrates multiple functions including asset custody and trade execution. Source: https://cryptobriefing.com/bitgo-regulated-trading-europe-bafin-approval/
Share
BitcoinEthereumNews2025/09/18 06:25