Ledger CTO Warns of NPM Supply-Chain Attack Hitting 1B+ Downloads

Sep 09 2025 crypto


According to Guillemet, the malicious code — already pushed into packages with over 1 billion downloads — is designed to silently swap crypto wallet addresses in transactions. That means unsuspecting users could send funds directly to the attacker without realizing it.



We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.