The post Ledger CTO Warns of Billion-Download NPM Supply Chain Attack, All Solana Ecosystem Responds appeared on BitcoinEthereumNews.com. Ledger CTO Charles Guillemet has sounded the alarm on a major supply chain attack targeting the JavaScript ecosystem. The exploit comes after a reputable developer’s NPM account was compromised, pushing malicious code into widely used packages with over 1 billion downloads. On X, Guillemet wrote: “There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.” 🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works… — Charles Guillemet (@P3b7_) September 8, 2025 Malicious Payload Swaps Crypto Addresses The injected payload is designed to silently replace crypto addresses during transactions. If a user pastes or inputs a wallet address, the code swaps it with the attacker’s address—stealing funds without the victim realizing. NPM has already disabled the compromised versions, but Guillemet cautions that risks may remain, especially on frontend applications still relying on cached or unpatched code. He advised:  Hardware wallet users should double-check every transaction before signing.  Software wallet users should pause all on-chain activity until further clarity. At this stage, it’s not clear if the attacker is also harvesting seed phrases from software wallets. Solana Ecosystem Responds The attack has triggered responses across the Solana ecosystem. Protocols and wallets quickly issued statements clarifying their exposure—or lack thereof. Drift Protocol Solana-based Drift Protocol Drift confirms that Drift’s SDK and UI are not affected by the large-scale NPM supply chain attack. None of the compromised packages were identified in Drift’s codebase. For the safety of the community, Drift advises users… The post Ledger CTO Warns of Billion-Download NPM Supply Chain Attack, All Solana Ecosystem Responds appeared on BitcoinEthereumNews.com. Ledger CTO Charles Guillemet has sounded the alarm on a major supply chain attack targeting the JavaScript ecosystem. The exploit comes after a reputable developer’s NPM account was compromised, pushing malicious code into widely used packages with over 1 billion downloads. On X, Guillemet wrote: “There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.” 🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works… — Charles Guillemet (@P3b7_) September 8, 2025 Malicious Payload Swaps Crypto Addresses The injected payload is designed to silently replace crypto addresses during transactions. If a user pastes or inputs a wallet address, the code swaps it with the attacker’s address—stealing funds without the victim realizing. NPM has already disabled the compromised versions, but Guillemet cautions that risks may remain, especially on frontend applications still relying on cached or unpatched code. He advised:  Hardware wallet users should double-check every transaction before signing.  Software wallet users should pause all on-chain activity until further clarity. At this stage, it’s not clear if the attacker is also harvesting seed phrases from software wallets. Solana Ecosystem Responds The attack has triggered responses across the Solana ecosystem. Protocols and wallets quickly issued statements clarifying their exposure—or lack thereof. Drift Protocol Solana-based Drift Protocol Drift confirms that Drift’s SDK and UI are not affected by the large-scale NPM supply chain attack. None of the compromised packages were identified in Drift’s codebase. For the safety of the community, Drift advises users…

Ledger CTO Warns of Billion-Download NPM Supply Chain Attack, All Solana Ecosystem Responds

Ledger CTO Charles Guillemet has sounded the alarm on a major supply chain attack targeting the JavaScript ecosystem.

The exploit comes after a reputable developer’s NPM account was compromised, pushing malicious code into widely used packages with over 1 billion downloads.

On X, Guillemet wrote:

Malicious Payload Swaps Crypto Addresses

The injected payload is designed to silently replace crypto addresses during transactions. If a user pastes or inputs a wallet address, the code swaps it with the attacker’s address—stealing funds without the victim realizing.

NPM has already disabled the compromised versions, but Guillemet cautions that risks may remain, especially on frontend applications still relying on cached or unpatched code.

He advised:

  •  Hardware wallet users should double-check every transaction before signing.
  •  Software wallet users should pause all on-chain activity until further clarity.

At this stage, it’s not clear if the attacker is also harvesting seed phrases from software wallets.

Solana Ecosystem Responds

The attack has triggered responses across the Solana ecosystem. Protocols and wallets quickly issued statements clarifying their exposure—or lack thereof.

Drift Protocol

Solana-based Drift Protocol

confirmed that both its SDK and UI remain unaffected. The team advised users to stay alert when signing any transactions until wallets fully confirm safety.

Solflare Wallet

Popular Solana wallet Solflare

said its users are not at risk. The team pointed to safeguards like version locking and thorough code reviews before merging updates. Minor version changes are never pushed without review.

Kamino Finance

Kamino Finance co-founder @y2kappa

responded, confirming Solana’s leading lending protocol is not exposed. The Kamino app has no dependency on the compromised NPM packages.

Marinade Finance

Staking giant Marinade Finance

said it is monitoring the situation closely. Initial checks show no impact, but the team urged users to remain vigilant as details unfold.

Jupiter Exchange

Solana’s top DEX aggregator Jupiter Exchange

confirmed it is safe. Neither the Jupiter web app nor Jup Mobile relies on the compromised versions.

Supply Chain Attacks: A Growing Risk

This incident highlights the fragility of open-source ecosystems. With NPM packages embedded across thousands of projects, a single compromised account can spread malicious code to millions of users overnight.

The risk is amplified in crypto, where address swaps can directly drain wallets. Unlike traditional hacks, supply chain attacks exploit trust in widely used libraries, slipping past most developers and security tools.

What Users Should Do

Guillemet’s advice is clear:

  • Hardware wallets remain the safest option. Always verify the transaction address on the device before approving.
  • Software wallet users should avoid sending transactions until updates confirm no deeper compromise.
  • Developers should review package dependencies and ensure they are not pulling from compromised versions.

As of now, the attack appears contained, with NPM disabling malicious versions. But questions remain. Is the attacker only hijacking addresses—or also attempting to exfiltrate seeds from software wallets? The answer could determine whether this is an inconvenience for careless users or a catastrophic breach across the industry.

For now, caution is the rule. Guillemet’s warning underscores how even one compromised developer account can threaten an entire ecosystem. With over 1 billion downloads at risk, this NPM attack may go down as one of the most significant supply chain compromises in recent memory.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Source: https://nulltx.com/ledger-cto-warns-of-billion-download-npm-supply-chain-attack-all-solana-ecosystem-responds/

Market Opportunity
SEED Logo
SEED Price(SEED)
$0.0004777
$0.0004777$0.0004777
+0.14%
USD
SEED (SEED) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The UA Sprinkler Fitters Local 669 JATC – Notice of Privacy Incident

The UA Sprinkler Fitters Local 669 JATC – Notice of Privacy Incident

Landover, Maryland, February 6, 2026– The UA Sprinkler Fitters Local 669 Joint Apprenticeship and Training Committee (“JATC”) is providing notice of an event that
Share
AI Journal2026/02/07 07:30
3 Paradoxes of Altcoin Season in September

3 Paradoxes of Altcoin Season in September

The post 3 Paradoxes of Altcoin Season in September appeared on BitcoinEthereumNews.com. Analyses and data indicate that the crypto market is experiencing its most active altcoin season since early 2025, with many altcoins outperforming Bitcoin. However, behind this excitement lies a paradox. Most retail investors remain uneasy as their portfolios show little to no profit. This article outlines the main reasons behind this situation. Altcoin Market Cap Rises but Dominance Shrinks Sponsored TradingView data shows that the TOTAL3 market cap (excluding BTC and ETH) reached a new high of over $1.1 trillion in September. Yet the share of OTHERS (excluding the top 10) has declined since 2022, now standing at just 8%. OTHERS Dominance And TOTAL3 Capitalization. Source: TradingView. In past cycles, such as 2017 and 2021, TOTAL3 and OTHERS.D rose together. That trend reflected capital flowing not only into large-cap altcoins but also into mid-cap and low-cap ones. The current divergence shows that capital is concentrated in stablecoins and a handful of top-10 altcoins such as SOL, XRP, BNB, DOG, HYPE, and LINK. Smaller altcoins receive far less liquidity, making it hard for their prices to return to levels where investors previously bought. This creates a situation where only a few win while most face losses. Retail investors also tend to diversify across many coins instead of adding size to top altcoins. That explains why many portfolios remain stagnant despite a broader market rally. Sponsored “Position sizing is everything. Many people hold 25–30 tokens at once. A 100x on a token that makes up only 1% of your portfolio won’t meaningfully change your life. It’s better to make a few high-conviction bets than to overdiversify,” analyst The DeFi Investor said. Altcoin Index Surges but Investor Sentiment Remains Cautious The Altcoin Season Index from Blockchain Center now stands at 80 points. This indicates that over 80% of the top 50 altcoins outperformed…
Share
BitcoinEthereumNews2025/09/18 01:43
After Solana’s Surge, BlockchainFX Steps In – Where the Next Wave of Crypto Millionaires Will Come From in 2025

After Solana’s Surge, BlockchainFX Steps In – Where the Next Wave of Crypto Millionaires Will Come From in 2025

The post After Solana’s Surge, BlockchainFX Steps In – Where the Next Wave of Crypto Millionaires Will Come From in 2025 appeared on BitcoinEthereumNews.com. Crypto News 18 September 2025 | 13:26 What if you could go back in time and grab Solana under $1 before it exploded to hundreds? That kind of regret has created countless crypto millionaire stories—and now history is setting up to repeat. BlockchainFX ($BFX) is shaping up as the best crypto presale of 2025, already live, generating revenue, and rewarding early buyers with daily USDT payouts. Meanwhile, coins like Solana are trading above $230, far beyond their presale glory days. This is not just hype—it’s a new crypto presale 2025 with real utility, a working product, and financial incentives that scream urgency. Those who act now could lock in life-changing gains before prices climb higher. Secure your $BFX today—don’t miss your second chance at a 1000x potential presale. BlockchainFX Presale: Why This Could Be the Next 100x Crypto of 2025 BlockchainFX isn’t a whitepaper dream—it’s a live trading super app combining crypto, stocks, forex, and commodities in one place. With 10,000+ daily users, a CertiK audit, and millions already processed in trading volume, BFX is backed by proof, not promises. The presale started at just $0.01. That chance is gone—today it trades at $0.024, with scheduled price increases every Monday until the confirmed launch at $0.05. Over $7.5 million has been raised from nearly 10,000 participants, all chasing explosive presale profits. The rewards are unmatched: up to 70% of platform fees redistributed daily as USDT, generating 4–7% per day returns and 90% APY even during presale. Token holders also unlock BFX Visa cards for real-world spending. Add in a $500,000 giveaway contest and listings confirmed on five centralized exchanges, and the urgency becomes crystal clear. Forecasts project $0.10–$0.25 post-launch, with long-term upside potentially crossing $1. A $5,000 entry at today’s price could balloon into over $200,000 if long-term targets play…
Share
BitcoinEthereumNews2025/09/18 18:32