Crypto News

Ledger CTO Warns of Supply Chain Attack, Cautions Against On-Chain Transactions

Published by

The JavaScript ecosystem is under a massive threat following a major supply chain attack. Hence, millions of crypto users and developers are now at risk. With more than a billion of these packages downloaded already, thousands of blockchain wallets and applications could be suffer varying exploits.

Supply Chain Attack Injects Malware Into Core NPM Packages

Ledger CTO Charles Guillemet warned that a compromised Node Package Manager (NPM) account has led to malicious updates in widely used packages, including error-ex, color-convert, and strip-ansi. Security researchers discovered that the injected malware functions as a “crypto-clipper.” It silently hijacks wallet addresses in network requests and replaces them with addresses controlled by the attacker.


The supply chain attack activates whether or not a crypto wallet is detected. If a wallet such as MetaMask is present, the malware directly intercepts and manipulates transaction requests.  It scans data for wallet addresses in Bitcoin, Ethereum, Solana, Tron, Litecoin, and other networks.

These are replaced with similar-looking attacker addresses using a string-matching algorithm. The deception makes it difficult for victims to notice changes. Recently, World Liberty Financial disclosed why it blacklisted 272 wallets, highlighting broader risks facing wallet security.

Developers first spotted the malicious code from the supply chain attack after a cryptic build failure during a pipeline run. Instead of the stable version 1.3.2, their systems installed a newly published 1.3.3 version of error-ex. That release contained heavily obfuscated code, including a suspicious function named checkethereumw. Investigation confirmed it was stealing crypto data and redirecting funds.

Developers Urged to Strengthen Defenses as Supply Chain Threat Widens

Guillemet urged caution. He advised users with hardware wallets to carefully check each transaction before signing. For those without hardware protection, he recommended pausing all on-chain transactions until the threat is resolved. He added that it remains unclear whether attackers can directly steal wallet seed phrases from software wallets.

New revelations, including a report by Arkham about the 127,426 Bitcoin hack on the Lubian mining pool, highlights the possible extent of exploits, including a supply chain attack. Despite mounting fears, Solana’s top DEX-aggregator Jupiter said it is unaffected. The team said Jupiter and Jup Mobile do not use compromised package versions. They added that they’ve reviewed the source code and assured users their products are safe.

Share
Paul Adedoyin

Paul Adedoyin is a crypto journalist with 4+ years experience who provides timely news, in-depth research, and insightful content to inform and empower his audience. His works have been featured on sites such as CryptoMode, CryptoNewsFlash among others. He holds a degree in Geophysics from OAU, Nigeria. When he's not writing, he loves watching soccer and reading educative journals. He can be reached via paul@coingape.com

Published by

Recent Posts

  • Crypto News

XRP News: Senator Warren Blocks Fed Master Accounts for Ripple, Crypto Firms in CLARITY Act

In significant XRP news today, Senator Elizabeth Warren submits more than 40 amendments to the…

May 13, 2026
  • Crypto News

Trump’s China Visit: Bitcoin Gains as Nvidia’s Jensen Huang Joins Elon Musk, Top CEOs

President Donald Trump is on a state visit to China this week, marking the first…

May 13, 2026
  • Bitcoin News

Strategy’s STRC Attracts $240M Capital As Michael Saylor Lauds CLARITY Act

Strategy's STRC raised an estimated $240.13 million net proceeds with its at-the-market (ATM) program. It…

May 13, 2026
  • Regulation News

CLARITY Act: Galaxy’s Alex Thorn Reveals Secret To Securing Bipartisan Support

Galaxy Digital's Alex Thorn says the newest edition of the CLARITY Act could get a…

May 13, 2026
  • Ethereum News

Breaking: JPMorgan Files For Ethereum Tokenized Money Market Fund After BlackRock

JPMorgan Chase & Co. is ramping up its blockchain-related initiatives. It aims to introduce a…

May 13, 2026
  • Exchange News

Kraken Parent Payward Partners Franklin Templeton To Launch Tokenized Securities

Payward, the parent company behind crypto exchange Kraken, has joined forces with global asset manager…

May 13, 2026