Ledger CTO Warns Of Crypto Clipper Malware Following Major NPM Breach

Source Bitcoinist

A significant supply chain attack has raised alarms within the cryptocurrency community, especially after the Node Package Manager (NPM) account of developer Qix was compromised.

Charles Guilletment, the Chief Technology Officer of Ledger, a hardware wallet provider, issued a stark warning to crypto investors in a recent post on social media platform X (formerly Twitter). 

He highlighted the potential risks associated with this breach, noting that the affected packages have been downloaded over a billion times, putting the entire JavaScript ecosystem in jeopardy.

Crypto Clipper Malware Discovered

According to an investigative report on the matter, the malicious code introduced in this attack functions as a “crypto-clipper,” a type of malware designed to intercept and alter cryptocurrency transactions. 

The malicious code is said to operate by silently swapping wallet addresses in network requests, effectively redirecting funds from legitimate wallets to those controlled by the attacker. 

For users of hardware wallets, Guilletment advised that careful attention should be paid to every transaction before signing. In contrast, he urged individuals who do not utilize hardware wallets to refrain from any on-chain transactions until the situation is fully resolved. 

In light of the breach, a crypto expert has confirmed that they are collaborating with the NPM security team to address the issue. While the malicious code has been removed from most of the compromised packages, the situation remains fluid. 

Urgent Security Measures

The supply chain attack specifically involved the developer known as Qix, leading to the publication of malicious versions of numerous high-impact packages. With the combined weekly downloads of these affected packages surpassing one billion, the potential impact on the JavaScript ecosystem is substantial.

To mitigate risks, Guilletment emphasized the importance of auditing project dependencies immediately. Developers are encouraged to pin all affected packages to their last known safe versions using the overrides feature in their package.json files. 

Crypto

Featured image from DALL-E, chart from TradingView.com 

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
TSMC Q3 Earnings Preview: Record Revenue Is a Lock, but an Upgraded Outlook Could Be the Real CatalystGlobal semiconductor foundry leader Taiwan Semiconductor Manufacturing Company (TSMC, TSM) will report its Q3 2025 earnings on Thursday, October 16, before U.S. markets open.
Author  TradingKey
12 hours ago
Global semiconductor foundry leader Taiwan Semiconductor Manufacturing Company (TSMC, TSM) will report its Q3 2025 earnings on Thursday, October 16, before U.S. markets open.
placeholder
Intel Downgraded by BofA and HSBC: Is a 50% Monthly Surge Overly Optimistic?HSBC has lowered Intel's rating from "Hold" to "Reduce," and Bank of America has adjusted its rating from "Neutral" to "Underperform".
Author  TradingKey
12 hours ago
HSBC has lowered Intel's rating from "Hold" to "Reduce," and Bank of America has adjusted its rating from "Neutral" to "Underperform".
placeholder
Powell Speech Preview: Will Fed Chair confirm two more rate cuts?With the US government shutdown causing key data releases to be postponed, Powell's comments could influence the US Dollar's valuation in the near term.
Author  FXStreet
12 hours ago
With the US government shutdown causing key data releases to be postponed, Powell's comments could influence the US Dollar's valuation in the near term.
placeholder
Aave Price Forecast: AAVE slips below $260 as on-chain metrics turn bearishAave (AAVE) price trade below $260 at the time of writing on Tuesday as the token faces weakness around its key resistance zone.
Author  FXStreet
14 hours ago
Aave (AAVE) price trade below $260 at the time of writing on Tuesday as the token faces weakness around its key resistance zone.
placeholder
WTI Oil drops to the $58.00 area as global trade fears resurfaceThe US benchmark West Texas Intermediate Oil has lost nearly $1 per barrel on Tuesday, retreating to levels near $58.00.
Author  FXStreet
14 hours ago
The US benchmark West Texas Intermediate Oil has lost nearly $1 per barrel on Tuesday, retreating to levels near $58.00.
goTop
quote