#Ledger CTO: A large-scale supply chain attack is ongoing: the NPM account of a reputable developer has been compromised. The affected packages have been downloaded more than 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
Malicious payload is attempting to steal funds by secretly altering crypto addresses.
🔐 If you are using a hardware wallet, carefully check each transaction before signing, and you are safe.
⚠️ If you are not using a hardware wallet, avoid performing on-chain transactions for now.
It is still unclear whether the attacker directly stole the seed ( keyword) from the software wallets.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
#Ledger CTO: A large-scale supply chain attack is ongoing: the NPM account of a reputable developer has been compromised. The affected packages have been downloaded more than 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
Malicious payload is attempting to steal funds by secretly altering crypto addresses.
🔐 If you are using a hardware wallet, carefully check each transaction before signing, and you are safe.
⚠️ If you are not using a hardware wallet, avoid performing on-chain transactions for now.
It is still unclear whether the attacker directly stole the seed ( keyword) from the software wallets.