The post Ledger CTO Warns of Billion-Download NPM Supply Chain Attack, All Solana Ecosystem Responds appeared on BitcoinEthereumNews.com. Ledger CTO Charles Guillemet has sounded the alarm on a major supply chain attack targeting the JavaScript ecosystem. The exploit comes after a reputable developer’s NPM account was compromised, pushing malicious code into widely used packages with over 1 billion downloads. On X, Guillemet wrote: “There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.” 🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works… — Charles Guillemet (@P3b7_) September 8, 2025 Malicious Payload Swaps Crypto Addresses The injected payload is designed to silently replace crypto addresses during transactions. If a user pastes or inputs a wallet address, the code swaps it with the attacker’s address—stealing funds without the victim realizing. NPM has already disabled the compromised versions, but Guillemet cautions that risks may remain, especially on frontend applications still relying on cached or unpatched code. He advised:  Hardware wallet users should double-check every transaction before signing.  Software wallet users should pause all on-chain activity until further clarity. At this stage, it’s not clear if the attacker is also harvesting seed phrases from software wallets. Solana Ecosystem Responds The attack has triggered responses across the Solana ecosystem. Protocols and wallets quickly issued statements clarifying their exposure—or lack thereof. Drift Protocol Solana-based Drift Protocol Drift confirms that Drift’s SDK and UI are not affected by the large-scale NPM supply chain attack. None of the compromised packages were identified in Drift’s codebase. For the safety of the community, Drift advises users… The post Ledger CTO Warns of Billion-Download NPM Supply Chain Attack, All Solana Ecosystem Responds appeared on BitcoinEthereumNews.com. Ledger CTO Charles Guillemet has sounded the alarm on a major supply chain attack targeting the JavaScript ecosystem. The exploit comes after a reputable developer’s NPM account was compromised, pushing malicious code into widely used packages with over 1 billion downloads. On X, Guillemet wrote: “There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.” 🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works… — Charles Guillemet (@P3b7_) September 8, 2025 Malicious Payload Swaps Crypto Addresses The injected payload is designed to silently replace crypto addresses during transactions. If a user pastes or inputs a wallet address, the code swaps it with the attacker’s address—stealing funds without the victim realizing. NPM has already disabled the compromised versions, but Guillemet cautions that risks may remain, especially on frontend applications still relying on cached or unpatched code. He advised:  Hardware wallet users should double-check every transaction before signing.  Software wallet users should pause all on-chain activity until further clarity. At this stage, it’s not clear if the attacker is also harvesting seed phrases from software wallets. Solana Ecosystem Responds The attack has triggered responses across the Solana ecosystem. Protocols and wallets quickly issued statements clarifying their exposure—or lack thereof. Drift Protocol Solana-based Drift Protocol Drift confirms that Drift’s SDK and UI are not affected by the large-scale NPM supply chain attack. None of the compromised packages were identified in Drift’s codebase. For the safety of the community, Drift advises users…

Ledger CTO Warns of Billion-Download NPM Supply Chain Attack, All Solana Ecosystem Responds

Ledger CTO Charles Guillemet has sounded the alarm on a major supply chain attack targeting the JavaScript ecosystem.

The exploit comes after a reputable developer’s NPM account was compromised, pushing malicious code into widely used packages with over 1 billion downloads.

On X, Guillemet wrote:

Malicious Payload Swaps Crypto Addresses

The injected payload is designed to silently replace crypto addresses during transactions. If a user pastes or inputs a wallet address, the code swaps it with the attacker’s address—stealing funds without the victim realizing.

NPM has already disabled the compromised versions, but Guillemet cautions that risks may remain, especially on frontend applications still relying on cached or unpatched code.

He advised:

  •  Hardware wallet users should double-check every transaction before signing.
  •  Software wallet users should pause all on-chain activity until further clarity.

At this stage, it’s not clear if the attacker is also harvesting seed phrases from software wallets.

Solana Ecosystem Responds

The attack has triggered responses across the Solana ecosystem. Protocols and wallets quickly issued statements clarifying their exposure—or lack thereof.

Drift Protocol

Solana-based Drift Protocol

confirmed that both its SDK and UI remain unaffected. The team advised users to stay alert when signing any transactions until wallets fully confirm safety.

Solflare Wallet

Popular Solana wallet Solflare

said its users are not at risk. The team pointed to safeguards like version locking and thorough code reviews before merging updates. Minor version changes are never pushed without review.

Kamino Finance

Kamino Finance co-founder @y2kappa

responded, confirming Solana’s leading lending protocol is not exposed. The Kamino app has no dependency on the compromised NPM packages.

Marinade Finance

Staking giant Marinade Finance

said it is monitoring the situation closely. Initial checks show no impact, but the team urged users to remain vigilant as details unfold.

Jupiter Exchange

Solana’s top DEX aggregator Jupiter Exchange

confirmed it is safe. Neither the Jupiter web app nor Jup Mobile relies on the compromised versions.

Supply Chain Attacks: A Growing Risk

This incident highlights the fragility of open-source ecosystems. With NPM packages embedded across thousands of projects, a single compromised account can spread malicious code to millions of users overnight.

The risk is amplified in crypto, where address swaps can directly drain wallets. Unlike traditional hacks, supply chain attacks exploit trust in widely used libraries, slipping past most developers and security tools.

What Users Should Do

Guillemet’s advice is clear:

  • Hardware wallets remain the safest option. Always verify the transaction address on the device before approving.
  • Software wallet users should avoid sending transactions until updates confirm no deeper compromise.
  • Developers should review package dependencies and ensure they are not pulling from compromised versions.

As of now, the attack appears contained, with NPM disabling malicious versions. But questions remain. Is the attacker only hijacking addresses—or also attempting to exfiltrate seeds from software wallets? The answer could determine whether this is an inconvenience for careless users or a catastrophic breach across the industry.

For now, caution is the rule. Guillemet’s warning underscores how even one compromised developer account can threaten an entire ecosystem. With over 1 billion downloads at risk, this NPM attack may go down as one of the most significant supply chain compromises in recent memory.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Source: https://nulltx.com/ledger-cto-warns-of-billion-download-npm-supply-chain-attack-all-solana-ecosystem-responds/

Market Opportunity
SEED Logo
SEED Price(SEED)
$0.000478
$0.000478$0.000478
+0.20%
USD
SEED (SEED) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Cashing In On University Patents Means Giving Up On Our Innovation Future

Cashing In On University Patents Means Giving Up On Our Innovation Future

The post Cashing In On University Patents Means Giving Up On Our Innovation Future appeared on BitcoinEthereumNews.com. “It’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress,” writes Pipes. Getty Images Washington is addicted to taxing success. Now, Commerce Secretary Howard Lutnick is floating a plan to skim half the patent earnings from inventions developed at universities with federal funding. It’s being sold as a way to shore up programs like Social Security. In reality, it’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress. Yes, taxpayer dollars support early-stage research. But the real payoff comes later—in the jobs created, cures discovered, and industries launched when universities and private industry turn those discoveries into real products. By comparison, the sums at stake in patent licensing are trivial. Universities collectively earn only about $3.6 billion annually in patent income—less than the federal government spends on Social Security in a single day. Even confiscating half would barely register against a $6 trillion federal budget. And yet the damage from such a policy would be anything but trivial. The true return on taxpayer investment isn’t in licensing checks sent to Washington, but in the downstream economic activity that federally supported research unleashes. Thanks to the bipartisan Bayh-Dole Act of 1980, universities and private industry have powerful incentives to translate early-stage discoveries into real-world products. Before Bayh-Dole, the government hoarded patents from federally funded research, and fewer than 5% were ever licensed. Once universities could own and license their own inventions, innovation exploded. The result has been one of the best returns on investment in government history. Since 1996, university research has added nearly $2 trillion to U.S. industrial output, supported 6.5 million jobs, and launched more than 19,000 startups. Those companies pay…
Share
BitcoinEthereumNews2025/09/18 03:26
Silver Price Crash Is Over “For Real This Time,” Analyst Predicts a Surge Back Above $90

Silver Price Crash Is Over “For Real This Time,” Analyst Predicts a Surge Back Above $90

Silver has been taking a beating lately, and the Silver price hasn’t exactly been acting like a safe haven. After running up into the highs, the whole move reversed
Share
Captainaltcoin2026/02/07 03:15
Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook

Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook

The post Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook appeared on BitcoinEthereumNews.com. Ethereum Price Prediction: Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook Disclaimer: The information found on NewsBTC is for educational purposes only. It does not represent the opinions of NewsBTC on whether to buy, sell or hold any investments and naturally investing carries risks. You are advised to conduct your own research before making any investment decisions. Use information provided on this website entirely at your own risk. Related News © 2025 NewsBTC. All Rights Reserved. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://www.newsbtc.com/news/ethereum/ethereum-price-prediction-citi-caps-year-end-at-4300-but-etf-outflows-challenge-outlook/
Share
BitcoinEthereumNews2025/09/18 14:30