Skip to content
September 8, 2025Bitcoinist logoBitcoinist

Ledger CTO Warns Of Crypto Clipper Malware Following Major NPM Breach

A significant supply chain attack has raised alarms within the cryptocurrency community, especially after the Node Package Manager (NPM) account of developer Qix was ￰0￱ Guilletment, the Chief Technology Officer of Ledger, a hardware wallet provider, issued a stark warning to crypto investors in a recent post on social media platform X (formerly Twitter). He highlighted the potential risks associated with this breach, noting that the affected packages have been downloaded over a billion times, putting the entire JavaScript ecosystem in ￰1￱ Clipper Malware Discovered According to an investigative report on the matter, the malicious code introduced in this attack functions as a “crypto-clipper,” a type of malware designed to intercept and alter cryptocurrency ￰2￱ malicious code is said to operate by silently swapping wallet addresses in network requests, effectively redirecting funds from legitimate wallets to those controlled by the ￰3￱ users of hardware wallets, Guilletment advised that careful attention should be paid to every transaction before ￰4￱ contrast, he urged individuals who do not utilize hardware wallets to refrain from any on-chain transactions until the situation is fully ￰5￱ light of the breach, a crypto expert has confirmed that they are collaborating with the NPM security team to address the ￰6￱ the malicious code has been removed from most of the compromised packages, the situation remains ￰7￱ Security Measures The supply chain attack specifically involved the developer known as Qix, leading to the publication of malicious versions of numerous high-impact ￰8￱ the combined weekly downloads of these affected packages surpassing one billion, the potential impact on the JavaScript ecosystem is ￰9￱ mitigate risks, Guilletment emphasized the importance of auditing project dependencies ￰10￱ are encouraged to pin all affected packages to their last known safe versions using the overrides feature in their ￰11￱ ￰12￱ image from DALL-E, chart from ￰13￱

Bitcoinist logo
Bitcoinist

Latest news and analysis from Bitcoinist

Ledger Nano Gen5 feels like Flex for less

Ledger Nano Gen5 feels like Flex for less

Companion “Wallet” software now includes an “Enterprise Multisig” built on Safe, but adds on-device clear signing...

Blockworks logoBlockworks
1 min
Watch Out: A Cryptocurrency Wallet is Ceasing Operations, Funds Must Be Withdrawn – Previously Made Headlines with XRP

Watch Out: A Cryptocurrency Wallet is Ceasing Operations, Funds Must Be Withdrawn – Previously Made Headlines with XRP

Cryptocurrency wallet manufacturer Ellipal announced that it will discontinue its hot wallet services and focus entirely on cold wallet technology. This decision comes after the recent alleged XRP the...

BitcoinSistemi logoBitcoinSistemi
1 min
Adrian Wall of Digital Sovereignty Alliance Advocates Digital Sovereignty and Financial Inclusion at UN General Assembly

Adrian Wall of Digital Sovereignty Alliance Advocates Digital Sovereignty and Financial Inclusion at UN General Assembly

This content is provided by a sponsor. PRESS RELEASE. Washington, D.C., October 23, 2025 — The Digital Sovereignty Alliance (DSA), a nonprofit organization dedicated to advancing clear and ethical pub...

Bitcoin.com logoBitcoin.com
1 min