Ledger CTO warns of massive supply attack targeting crypto users

來源 Cryptopolitan

A widespread supply chain attack has been discovered, potentially tracking data from a crypto wallet and stealing assets on all chains. The npm library of a big and trusted account has been compromised, researchers announced. 

A widespread npm supply chain attack is potentially targeting the owners of the most common crypto wallets. Charles Guillemet, CTO of Ledger, warned users to avoid crypto transactions using common browser-based or desktop wallets, and only transact through hardware wallets with great caution. 

Researchers discovered one of the trusted JavaScript npm accounts was spreading packages with malicious code that was able to track and even divert crypto transactions. Soon after the attack, the maintainer reached out to the community via a Hackernoon profile to warn that the affected packages are still mostly compromised and yet to be replaced with safe versions.

The npm maintainer’s account is still not recovered, and was most probably stolen through social engineering and a fake 2FA process. GitHub users reported a suspicious email originating from npmjs support. 

Ledger CTO Charles Guillemet: avoid crypto transactions, supply chain attack discovered
One of the JavaScript npm maintainers received a fake support email, leading to a compromised account and malicious crypto-stealing code injection into JavaScript packages. | Source: GitHub

The current event is viewed as the largest npm supply chain attack in history. More suppliers can be compromised if the emails manage to steal other accounts.

Large-scale supply chain attack targets software crypto wallets

In the past week, Cryptopolitan reported on two packages being compromised to steal crypto on Ethereum. 

The current attack is much larger – affecting a total of 18 highly popular npm packages, with 2B downloads in the past week. At this point, it is uncertain how many of the packages have spread through the JavaScript ecosystem. 

The supply chain attack is considered one of the biggest threats in the crypto space, potentially changing the destination of funds on the fly, despite the user seemingly signing the correct transaction. 

Once again, the biggest threat is against software wallet users, reportedly affecting MetaMask, Trust Wallet, Exodus, and others. All npm packages have been disabled, but developers must return to their code to discontinue the usage of the flawed packages. 

Users urged to avoid signing transactions until developers give a green light

For now, it is considered improbable that the attacker is capable of stealing private seeds directly, as it would expose even bigger problems with wallet security. Currently, user wallets are safe unless they send out or sign a transaction. 

The address swap happens before signing, as the attacker uses similar-looking destination wallets. The addresses look almost similar, requiring a detailed letter-by-letter verification before signing. Usually, crypto users check only the first and last four digits, leaving them open to address swap attacks. 

However, there are also smart contracts and automated transactions. End users are advised to lock and disable all browser wallets and refrain from signing transactions. The news also did not break down Monday’s crypto rally. Additionally, on-chain detectives have not sent out warnings of big or unusual losses from individual wallets.

The attack can affect all apps in the Web3 and DeFi ecosystem. Currently, transactions continue on all chains. Researchers have taken a screengrab of potential destination wallets, some of which are still empty. 

If you're reading this, you’re already ahead. Stay there with our newsletter.

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
澳洲央行升息25基點,澳幣匯率狂飆!未來走勢如何?澳洲央行2026年內大機率會再次升息,澳元兌美元漲勢或延續。
作者  Alison Ho
2 月 03 日 週二
澳洲央行2026年內大機率會再次升息,澳元兌美元漲勢或延續。
placeholder
日幣匯率巨震!自民黨大勝日本選舉,「高市交易」繼續?日股大漲,日經225指數漲超5%突破57000關口,創歷史新高。日幣匯率則先跌後漲,美元/日圓(USD/JPY)一度漲至157.72,後跌至156.21。
作者  Alison Ho
21 小時前
日股大漲,日經225指數漲超5%突破57000關口,創歷史新高。日幣匯率則先跌後漲,美元/日圓(USD/JPY)一度漲至157.72,後跌至156.21。
placeholder
美1月非農和CPI重磅來襲!年度就業或大幅下修?美元、黃金迎巨震!若非農數據大幅不如預期,將打擊美元、利好黃金價格上漲。若出現「就業弱+通膨強」的組合,市場波動或加劇。
作者  Alison Ho
17 小時前
若非農數據大幅不如預期,將打擊美元、利好黃金價格上漲。若出現「就業弱+通膨強」的組合,市場波動或加劇。
placeholder
黃金5000心理關口難定方向,「中繼」或僅剛剛開始黃金收復5000美元心理關口,新一輪升勢或仍需耐心等待;黃金「中繼」或僅剛剛開始,聚焦非農數據;黃金技術分析:高位整理格局,關注4600-5100區間
作者  Insights
14 小時前
黃金收復5000美元心理關口,新一輪升勢或仍需耐心等待;黃金「中繼」或僅剛剛開始,聚焦非農數據;黃金技術分析:高位整理格局,關注4600-5100區間
placeholder
【今日要聞】高市早苗大勝日本選舉,黃金價格重回5000美元高市早苗大勝日本選舉,日幣匯率先跌後漲;黃金價格重回5000美元,白銀漲超4%;美伊談判繼續,油價下跌>>
作者  Alison Ho
14 小時前
高市早苗大勝日本選舉,日幣匯率先跌後漲;黃金價格重回5000美元,白銀漲超4%;美伊談判繼續,油價下跌>>
goTop
quote