Ledger CTO Warns Of Crypto Clipper Malware Following Major NPM Breach

bitcoinistPublicado a 2025-09-08Actualizado a 2025-09-08

Resumen

A significant supply chain attack has raised alarms within the cryptocurrency community, especially after the Node Package Manager (NPM) account...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

A significant supply chain attack has raised alarms within the cryptocurrency community, especially after the Node Package Manager (NPM) account of developer Qix was compromised.

Charles Guilletment, the Chief Technology Officer of Ledger, a hardware wallet provider, issued a stark warning to crypto investors in a recent post on social media platform X (formerly Twitter). 

He highlighted the potential risks associated with this breach, noting that the affected packages have been downloaded over a billion times, putting the entire JavaScript ecosystem in jeopardy.

Crypto Clipper Malware Discovered

According to an investigative report on the matter, the malicious code introduced in this attack functions as a “crypto-clipper,” a type of malware designed to intercept and alter cryptocurrency transactions. 

The malicious code is said to operate by silently swapping wallet addresses in network requests, effectively redirecting funds from legitimate wallets to those controlled by the attacker. 

For users of hardware wallets, Guilletment advised that careful attention should be paid to every transaction before signing. In contrast, he urged individuals who do not utilize hardware wallets to refrain from any on-chain transactions until the situation is fully resolved. 

In light of the breach, a crypto expert has confirmed that they are collaborating with the NPM security team to address the issue. While the malicious code has been removed from most of the compromised packages, the situation remains fluid. 

Urgent Security Measures

The supply chain attack specifically involved the developer known as Qix, leading to the publication of malicious versions of numerous high-impact packages. With the combined weekly downloads of these affected packages surpassing one billion, the potential impact on the JavaScript ecosystem is substantial.

To mitigate risks, Guilletment emphasized the importance of auditing project dependencies immediately. Developers are encouraged to pin all affected packages to their last known safe versions using the overrides feature in their package.json files. 

Crypto
The daily chart shows the total crypto market cap valuation at $3.83 trillion. Source: TOTAL on TradingView.com

Featured image from DALL-E, chart from TradingView.com 

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Ronaldo is a seasoned crypto enthusiast with over four years of experience in the field. He is passionate about exploring the vast and dynamic world of decentralized finance (DeFi) and its practical applications for achieving economic sovereignty. Ronaldo is constantly seeking to expand his knowledge and expertise in the DeFi space, as he believes it holds tremendous potential for transforming the traditional financial landscape.

Lecturas Relacionadas

Ethereum cae un 45% desde principios de año: ¿Por qué SharpLink y las ballenas siguen comprando?

A pesar de la debilidad actual en el mercado de criptomonedas y de que Ethereum (ETH) ha caído entre un 20% y un 45% este año, continúa atrayendo el interés institucional. SharpLink reanudó sus compras después de ocho meses, adquiriendo 5.000 ETH por valor de aproximadamente 7,88 millones de dólares. Además, reforzó sus tenencias con 26.324K LSETH (45,54 millones de dólares), elevando su cartera total a 876.285 ETH. Esta acumulación, a pesar de las pérdidas no realizadas, sugiere una fuerte convicción en la utilidad a largo plazo de Ethereum y en los ingresos por staking. Por otro lado, las carteras de ballenas también están acumulando ETH. Una nueva cartera acumuló 18.361 ETH (28,9 millones de dólares) en nueve días, indicando una estrategia de exposición a futuro más que una reacción a los movimientos diarios del precio. Sin embargo, los ETF spot de Ethereum han experimentado salidas netas significativas, con una retirada de 12,85 millones de dólares el 26 de junio. Esta divergencia muestra que los compradores directos (tesorerías y ballenas) y los inversores en ETF están respondiendo a diferentes condiciones del mercado. En resumen, la acumulación por parte de instituciones y ballenas apunta a una confianza gradual en el futuro de Ethereum, pero una recuperación sostenida aún depende de que se reviertan las salidas de los ETF y de una mejora en la demanda general de la red.

ambcryptoHace 2 hora(s)

Ethereum cae un 45% desde principios de año: ¿Por qué SharpLink y las ballenas siguen comprando?

ambcryptoHace 2 hora(s)

Trading

Spot
活动图片