Ledger CTO Warns Of Crypto Clipper Malware Following Major NPM Breach

Source Bitcoinist

A significant supply chain attack has raised alarms within the cryptocurrency community, especially after the Node Package Manager (NPM) account of developer Qix was compromised.

Charles Guilletment, the Chief Technology Officer of Ledger, a hardware wallet provider, issued a stark warning to crypto investors in a recent post on social media platform X (formerly Twitter). 

He highlighted the potential risks associated with this breach, noting that the affected packages have been downloaded over a billion times, putting the entire JavaScript ecosystem in jeopardy.

Crypto Clipper Malware Discovered

According to an investigative report on the matter, the malicious code introduced in this attack functions as a “crypto-clipper,” a type of malware designed to intercept and alter cryptocurrency transactions. 

The malicious code is said to operate by silently swapping wallet addresses in network requests, effectively redirecting funds from legitimate wallets to those controlled by the attacker. 

For users of hardware wallets, Guilletment advised that careful attention should be paid to every transaction before signing. In contrast, he urged individuals who do not utilize hardware wallets to refrain from any on-chain transactions until the situation is fully resolved. 

In light of the breach, a crypto expert has confirmed that they are collaborating with the NPM security team to address the issue. While the malicious code has been removed from most of the compromised packages, the situation remains fluid. 

Urgent Security Measures

The supply chain attack specifically involved the developer known as Qix, leading to the publication of malicious versions of numerous high-impact packages. With the combined weekly downloads of these affected packages surpassing one billion, the potential impact on the JavaScript ecosystem is substantial.

To mitigate risks, Guilletment emphasized the importance of auditing project dependencies immediately. Developers are encouraged to pin all affected packages to their last known safe versions using the overrides feature in their package.json files. 

Crypto

Featured image from DALL-E, chart from TradingView.com 

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Asian Stocks Climb on US AI Optimism; Japan’s Nikkei Reaches New Record HighMost Asian stock markets climbed on Thursday, with China leading gains fueled by renewed optimism around U.S. artificial intelligence developments.
Author  Mitrade
Yesterday 06: 06
Most Asian stock markets climbed on Thursday, with China leading gains fueled by renewed optimism around U.S. artificial intelligence developments.
placeholder
Dollar Holds Steady Amid Inflation Data and Central Bank WatchThe U.S. dollar steadied in early Asian trading on Thursday following an unexpected 0.1% decline in the Producer Price Index (PPI) for final demand in August, as reported by the Labor Department’s Bureau of Labor Statistics.
Author  Mitrade
Yesterday 02: 44
The U.S. dollar steadied in early Asian trading on Thursday following an unexpected 0.1% decline in the Producer Price Index (PPI) for final demand in August, as reported by the Labor Department’s Bureau of Labor Statistics.
placeholder
Barclays Boosts S&P 500 Outlook Amid Strong AI-Driven EarningsBarclays has increased its earnings and price projections for the S&P 500 through 2025 and 2026, attributing the upgrade to stronger-than-anticipated corporate results in the first half of the year and a robust earnings landscape despite trade tensions and labor challenges.
Author  Mitrade
Sept 10, Wed
Barclays has increased its earnings and price projections for the S&P 500 through 2025 and 2026, attributing the upgrade to stronger-than-anticipated corporate results in the first half of the year and a robust earnings landscape despite trade tensions and labor challenges.
placeholder
ANZ Raises Gold Price Forecast to $3,800/Oz, Predicts Rally to Continue Through 2026Gold is expected to continue its upward momentum throughout 2025 and into early 2026, driven by ongoing geopolitical tensions, macroeconomic challenges, and market anticipation of U.S. monetary easing, according to analysts from ANZ in a research note released Wednesday.
Author  Mitrade
Sept 10, Wed
Gold is expected to continue its upward momentum throughout 2025 and into early 2026, driven by ongoing geopolitical tensions, macroeconomic challenges, and market anticipation of U.S. monetary easing, according to analysts from ANZ in a research note released Wednesday.
placeholder
Dollar steadies before U.S. jobs data; euro pressured by French turmoilThe U.S. dollar edged higher Tuesday, stabilizing after a slide to seven-week lows as traders looked ahead to key labor and inflation data expected to lock in a Federal Reserve rate cut next week.
Author  Mitrade
Sept 09, Tue
The U.S. dollar edged higher Tuesday, stabilizing after a slide to seven-week lows as traders looked ahead to key labor and inflation data expected to lock in a Federal Reserve rate cut next week.
goTop
quote