Ledger: the CTO alerts on an NPM flaw that threatens the safety of cryptos

A major flaw in the supply chain shook the open source community after hacking the Node Package Manager (NPM) account of a renowned developer. Highly used packages have been compromised, arousing strong concerns throughout the JavaScript ecosystem.

The Ledger technical director points to a screen displaying a digital threat based on NPM targeting a cryptocurrency wallet.

In short

  • Hackers have taken control of the NPM account of a recognized developer, triggering a Supply Chain attack which endangered the JavaScript community.
  • More than a billion downloads of compromised packets have raised fears of a massive exhibition.
  • Charles Guillemet, CTO de Ledger, recommended checking each transaction and using hardware wallets with secure display to protect themselves.

The NPM fault raises concerns for the safety of portfolios

Charles Guillemet, technical director of Ledger, detailed the magnitude of the threat: a major NPM account has been diverted and the infected packages have already been downloaded more than a billion times. Given this scope, he said that the entire JavaScript ecosystem could be exposed. The malicious code acted silently, changing in real time the cryptocurrency addresses to divert the funds to the attackers.

Guillemet called for caution. He clarified that the users of material portfolios remained protected provided that it will check each transaction before validation. For those who use software portfolios, he advised to suspend on-chain transactions until the situation is clarified. He also indicated that he had not yet been established if the attackers were looking to extract the SEEDS from the recovery of software portfolios directly.

An NPM developer confirms hacking

Maintaining the center of the fault, Josh Juno, confirmed that his NPM account had been compromised. In a post on Bluesky, he explained that The attack came from a phishing campaign. The attackers had created a false domain (“Support@npmjs[dot]Help ”) imitating the official NPMJS.com website.

Maintains received threatening emails saying that their accounts would be locked on September 10, 2025. These messages contained phishing links intended to steal their identifiers. The false message indicated in particular:

To maintain the safety and integrity of your account, we ask you to make this update as soon as possible. Please note that the accounts with an obsolete 2FA identifiers will be temporarily locked from September 10, 2025, in order to prevent unauthorized access.

Soon after, Other developers have reported that they were targetedconfirming that the campaign went far beyond the framework of a single account.

Reaction and technical analysis

The NPM team intervened quickly, deleting the malicious versions posted online. Among them was a version of the Debug package, downloaded several hundred million times every week, around 357 million according to estimates.

A complementary analysis Led by Aikido Security highlighted several points:

  • The malicious code had been inserted into the files index.js compromised packages, acting as an interceptor in the browser to target users of cryptos;
  • he embedded in browsers by diverting functions like fetch,, XMLHTTPREQUET and portfolios such as Window.ethereum And Solara ;
  • Once active, he identified wallet addresses (Ethereum, Bitcoin, Solana, Tron, Litecoin, Bitcoin Cash) and replaced them with those of attackers, often similar in appearance;
  • He modified the details of the transactions before signature (recipients, validations, authorizations), while retaining a normal interface, which redirected the funds;
  • It remained discreet, avoiding visible changes when a wallet was detected, and acted in the background.
Secures your cryptos with ledger
This link uses an affiliation program

A call to vigilance

In Coindesk declarations, Guillemet warned that decentralized applications and software wallets incorporating these compromised packages could be vulnerable, Exposing users to fundraising. He recalled that the best protection remained the use of a material wallet with a secure display and the Clear Signing.

This method makes it possible to check the address and details of each transaction directly on the device, guaranteeing correspondence with the real intention of the user.

“Always check your transactions, never sign blind,” he insisted. It systematically recommends the use of a wallet hardware with secure display.

Maximize your Cointribne experience with our 'Read to Earn' program! For each article you read, earn points and access exclusive rewards. Sign up now and start accumulating advantages.

Similar Posts