Ledger CTO warns of massive supply attack targeting crypto users

来源 Cryptopolitan

A widespread supply chain attack has been discovered, potentially tracking data from a crypto wallet and stealing assets on all chains. The npm library of a big and trusted account has been compromised, researchers announced. 

A widespread npm supply chain attack is potentially targeting the owners of the most common crypto wallets. Charles Guillemet, CTO of Ledger, warned users to avoid crypto transactions using common browser-based or desktop wallets, and only transact through hardware wallets with great caution. 

Researchers discovered one of the trusted JavaScript npm accounts was spreading packages with malicious code that was able to track and even divert crypto transactions. Soon after the attack, the maintainer reached out to the community via a Hackernoon profile to warn that the affected packages are still mostly compromised and yet to be replaced with safe versions.

The npm maintainer’s account is still not recovered, and was most probably stolen through social engineering and a fake 2FA process. GitHub users reported a suspicious email originating from npmjs support. 

Ledger CTO Charles Guillemet: avoid crypto transactions, supply chain attack discovered
One of the JavaScript npm maintainers received a fake support email, leading to a compromised account and malicious crypto-stealing code injection into JavaScript packages. | Source: GitHub

The current event is viewed as the largest npm supply chain attack in history. More suppliers can be compromised if the emails manage to steal other accounts.

Large-scale supply chain attack targets software crypto wallets

In the past week, Cryptopolitan reported on two packages being compromised to steal crypto on Ethereum. 

The current attack is much larger – affecting a total of 18 highly popular npm packages, with 2B downloads in the past week. At this point, it is uncertain how many of the packages have spread through the JavaScript ecosystem. 

The supply chain attack is considered one of the biggest threats in the crypto space, potentially changing the destination of funds on the fly, despite the user seemingly signing the correct transaction. 

Once again, the biggest threat is against software wallet users, reportedly affecting MetaMask, Trust Wallet, Exodus, and others. All npm packages have been disabled, but developers must return to their code to discontinue the usage of the flawed packages. 

Users urged to avoid signing transactions until developers give a green light

For now, it is considered improbable that the attacker is capable of stealing private seeds directly, as it would expose even bigger problems with wallet security. Currently, user wallets are safe unless they send out or sign a transaction. 

The address swap happens before signing, as the attacker uses similar-looking destination wallets. The addresses look almost similar, requiring a detailed letter-by-letter verification before signing. Usually, crypto users check only the first and last four digits, leaving them open to address swap attacks. 

However, there are also smart contracts and automated transactions. End users are advised to lock and disable all browser wallets and refrain from signing transactions. The news also did not break down Monday’s crypto rally. Additionally, on-chain detectives have not sent out warnings of big or unusual losses from individual wallets.

The attack can affect all apps in the Web3 and DeFi ecosystem. Currently, transactions continue on all chains. Researchers have taken a screengrab of potential destination wallets, some of which are still empty. 

If you're reading this, you’re already ahead. Stay there with our newsletter.

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
日本首相石破茂宣布辞职!日股大涨,日元汇率下挫石破茂下台将使日本推行更为扩张性的财政政策,进而利好日股、打击日元。
作者  Alison Ho
昨日 02: 33
石破茂下台将使日本推行更为扩张性的财政政策,进而利好日股、打击日元。
placeholder
黄金升破3600美元,再创历史新高!4000大关不远?突破3600美元后,黄金下一目标价看3700美元。高盛认为长期看黄金不排除涨至5000美元。
作者  Tony Chou
昨日 03: 37
突破3600美元后,黄金下一目标价看3700美元。高盛认为长期看黄金不排除涨至5000美元。
placeholder
非农引爆衰退恐慌!日本政局动荡,欧元、日元何去何从?【外汇周报】日本首相宣布辞职!政治风波下日元一度跌破149。非农引发美国衰退担忧,欧央行会议能否助力欧元/美元?
作者  Alison Ho
22 小时前
日本首相宣布辞职!政治风波下日元一度跌破149。非农引发美国衰退担忧,欧央行会议能否助力欧元/美元?
placeholder
【今日市场前瞻】黄金价格突破3610美元创新高!法国政坛将变天黄金价格突破3610美元,再创历史新高!法国政府信任投票在即,留意股票和汇率波动;特斯拉涨超1%>>
作者  Alison Ho
20 小时前
黄金价格突破3610美元,再创历史新高!法国政府信任投票在即,留意股票和汇率波动;特斯拉涨超1%>>
placeholder
9月9日财经早餐:10年期美债收益率、美元续跌,黄金、纳指创历史新高!Nebius盘后暴涨超46%美联储9月重启降息几乎已成定局,市场正等待本周四通胀数据公布以衡量FED9月大幅降息50基点可能。在滞涨风险与美联储更大规模降息预期中市场暂时保持乐观,VIX恐慌指数四连降,10年期美债收益率进一步跌至4.038%,续创两个月新低,美元进一步下跌,逼近97.4中长期关键支撑;黄金续创历史新高3646美元。投资者日内可重点关注美国劳工统计局发布非农年度基准修正数据。
作者  Insights
6 小时前
美联储9月重启降息几乎已成定局,市场正等待本周四通胀数据公布以衡量FED9月大幅降息50基点可能。在滞涨风险与美联储更大规模降息预期中市场暂时保持乐观,VIX恐慌指数四连降,10年期美债收益率进一步跌至4.038%,续创两个月新低,美元进一步下跌,逼近97.4中长期关键支撑;黄金续创历史新高3646美元。投资者日内可重点关注美国劳工统计局发布非农年度基准修正数据。
goTop
quote