Ledger CTO warns of massive supply attack targeting crypto users

來源 Cryptopolitan

A widespread supply chain attack has been discovered, potentially tracking data from a crypto wallet and stealing assets on all chains. The npm library of a big and trusted account has been compromised, researchers announced. 

A widespread npm supply chain attack is potentially targeting the owners of the most common crypto wallets. Charles Guillemet, CTO of Ledger, warned users to avoid crypto transactions using common browser-based or desktop wallets, and only transact through hardware wallets with great caution. 

Researchers discovered one of the trusted JavaScript npm accounts was spreading packages with malicious code that was able to track and even divert crypto transactions. Soon after the attack, the maintainer reached out to the community via a Hackernoon profile to warn that the affected packages are still mostly compromised and yet to be replaced with safe versions.

The npm maintainer’s account is still not recovered, and was most probably stolen through social engineering and a fake 2FA process. GitHub users reported a suspicious email originating from npmjs support. 

Ledger CTO Charles Guillemet: avoid crypto transactions, supply chain attack discovered
One of the JavaScript npm maintainers received a fake support email, leading to a compromised account and malicious crypto-stealing code injection into JavaScript packages. | Source: GitHub

The current event is viewed as the largest npm supply chain attack in history. More suppliers can be compromised if the emails manage to steal other accounts.

Large-scale supply chain attack targets software crypto wallets

In the past week, Cryptopolitan reported on two packages being compromised to steal crypto on Ethereum. 

The current attack is much larger – affecting a total of 18 highly popular npm packages, with 2B downloads in the past week. At this point, it is uncertain how many of the packages have spread through the JavaScript ecosystem. 

The supply chain attack is considered one of the biggest threats in the crypto space, potentially changing the destination of funds on the fly, despite the user seemingly signing the correct transaction. 

Once again, the biggest threat is against software wallet users, reportedly affecting MetaMask, Trust Wallet, Exodus, and others. All npm packages have been disabled, but developers must return to their code to discontinue the usage of the flawed packages. 

Users urged to avoid signing transactions until developers give a green light

For now, it is considered improbable that the attacker is capable of stealing private seeds directly, as it would expose even bigger problems with wallet security. Currently, user wallets are safe unless they send out or sign a transaction. 

The address swap happens before signing, as the attacker uses similar-looking destination wallets. The addresses look almost similar, requiring a detailed letter-by-letter verification before signing. Usually, crypto users check only the first and last four digits, leaving them open to address swap attacks. 

However, there are also smart contracts and automated transactions. End users are advised to lock and disable all browser wallets and refrain from signing transactions. The news also did not break down Monday’s crypto rally. Additionally, on-chain detectives have not sent out warnings of big or unusual losses from individual wallets.

The attack can affect all apps in the Web3 and DeFi ecosystem. Currently, transactions continue on all chains. Researchers have taken a screengrab of potential destination wallets, some of which are still empty. 

If you're reading this, you’re already ahead. Stay there with our newsletter.

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
​​00919配息開獎!0.72元穩了?達人拆解:三本柱夠厚,想配多少都不難​​市場矚目的00919(群益台灣精選高息)季配息金額即將揭曉,這檔規模突破4000億元的ETF霸主,上週五爆出17.6萬張大量,搶息買盤蜂擁而入,顯見市場對其維持0.72元高配息的預期極高。
作者  投資-槓把子
9 月 01 日 週一
市場矚目的00919(群益台灣精選高息)季配息金額即將揭曉,這檔規模突破4000億元的ETF霸主,上週五爆出17.6萬張大量,搶息買盤蜂擁而入,顯見市場對其維持0.72元高配息的預期極高。
placeholder
00918配息急墜25%!高息ETF神話破滅,26萬存股族心驚市場矚目的高股息ETF大華優利高填息30(00918)最新配息結果出爐,卻投下震撼彈!8月29日官方公告顯示,本次每單位僅配發0.52元,較前次的0.7元大幅縮水超過25%,創下該基金掛牌以來最大配息跌幅。
作者  投資-槓把子
9 月 01 日 週一
市場矚目的高股息ETF大華優利高填息30(00918)最新配息結果出爐,卻投下震撼彈!8月29日官方公告顯示,本次每單位僅配發0.52元,較前次的0.7元大幅縮水超過25%,創下該基金掛牌以來最大配息跌幅。
placeholder
搭上AI與散熱快車!漢磊成SiC概念新龍頭,暴漲背後是機會還是風險?漢磊宣布其碳化矽(SiC)第四代MOSFET製程平台(G4)實現突破。該公司總經理劉燦文表示,該技術不僅在晶片尺寸上縮小了20%,導通電阻也降低了20%,已達到「國際大廠水準」。
作者  投資-槓把子
21 小時前
漢磊宣布其碳化矽(SiC)第四代MOSFET製程平台(G4)實現突破。該公司總經理劉燦文表示,該技術不僅在晶片尺寸上縮小了20%,導通電阻也降低了20%,已達到「國際大廠水準」。
placeholder
9月9日財經早餐:10年期美債殖利率、美元續跌,黃金、納指創歷史新高!Nebius盤後暴漲超46%聯准會9月重啟降息幾乎已成定局,市場正等待本週四通脹數據公佈以衡量FED9月大幅降息50基點可能。在滯漲風險與聯准會更大規模降息預期中市場暫時保持樂觀,VIX恐慌指數四連降,10年期美債殖利率進一步跌至4.038%,續創兩個月新低,美元進一步下跌,逼近97.4中長期關鍵支撐;黃金續創歷史新高3646美元。投資者日內可重點關注美國勞工統計局發佈非農年度基準修正數據。
作者  Insights
3 小時前
聯准會9月重啟降息幾乎已成定局,市場正等待本週四通脹數據公佈以衡量FED9月大幅降息50基點可能。在滯漲風險與聯准會更大規模降息預期中市場暫時保持樂觀,VIX恐慌指數四連降,10年期美債殖利率進一步跌至4.038%,續創兩個月新低,美元進一步下跌,逼近97.4中長期關鍵支撐;黃金續創歷史新高3646美元。投資者日內可重點關注美國勞工統計局發佈非農年度基準修正數據。
placeholder
〈生技新星〉掛牌首日暴衝!大研生醫(7780)強漲衝破220元 董座喊話Q4動能更旺​投資慧眼Insights-大研生醫(7780)今日掛牌上市,早盤狂飆40%,股價衝上220元!
作者  投資指南針
1 小時前
​投資慧眼Insights-大研生醫(7780)今日掛牌上市,早盤狂飆40%,股價衝上220元!
goTop
quote