PANews reported on September 9th that Ledger CTO Charles Guillemet released an update on the NPM attack: "The attack failed, causing almost no losses to the victims. The attacker stole user credentials through a phishing email from a fake npm-supported domain and then released a malicious package update. The injected code targeted web encryption activities, invaded blockchain networks such as Ethereum and Solana, hijacked transactions, and directly replaced wallet addresses in network responses. Due to an attacker's operational error, the CI/CD process collapsed, allowing the attack to be discovered early and the impact to be limited. However, this is still a clear warning: if funds are stored in software wallets or exchanges, a single code execution can result in the loss of all funds. Supply chain security vulnerabilities remain a key vector for malware distribution, and targeted attacks are increasing. Hardware wallets are designed to protect against such threats. Features such as clear signatures confirm transaction details, and transaction checks can flag suspicious activity in advance. Although the current danger has passed, the threat still exists, so it is important to remain vigilant and ensure safety."PANews reported on September 9th that Ledger CTO Charles Guillemet released an update on the NPM attack: "The attack failed, causing almost no losses to the victims. The attacker stole user credentials through a phishing email from a fake npm-supported domain and then released a malicious package update. The injected code targeted web encryption activities, invaded blockchain networks such as Ethereum and Solana, hijacked transactions, and directly replaced wallet addresses in network responses. Due to an attacker's operational error, the CI/CD process collapsed, allowing the attack to be discovered early and the impact to be limited. However, this is still a clear warning: if funds are stored in software wallets or exchanges, a single code execution can result in the loss of all funds. Supply chain security vulnerabilities remain a key vector for malware distribution, and targeted attacks are increasing. Hardware wallets are designed to protect against such threats. Features such as clear signatures confirm transaction details, and transaction checks can flag suspicious activity in advance. Although the current danger has passed, the threat still exists, so it is important to remain vigilant and ensure safety."

Ledger CTO: NPM attackers failed, with few victims

2025/09/09 18:14
1 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

PANews reported on September 9th that Ledger CTO Charles Guillemet released an update on the NPM attack: "The attack failed, causing almost no losses to the victims. The attacker stole user credentials through a phishing email from a fake npm-supported domain and then released a malicious package update. The injected code targeted web encryption activities, invaded blockchain networks such as Ethereum and Solana, hijacked transactions, and directly replaced wallet addresses in network responses. Due to an attacker's operational error, the CI/CD process collapsed, allowing the attack to be discovered early and the impact to be limited. However, this is still a clear warning: if funds are stored in software wallets or exchanges, a single code execution can result in the loss of all funds. Supply chain security vulnerabilities remain a key vector for malware distribution, and targeted attacks are increasing. Hardware wallets are designed to protect against such threats. Features such as clear signatures confirm transaction details, and transaction checks can flag suspicious activity in advance. Although the current danger has passed, the threat still exists, so it is important to remain vigilant and ensure safety."

Opportunità di mercato
Logo Ambire Wallet
Valore Ambire Wallet (WALLET)
$0,01183
$0,01183$0,01183
+0,16%
USD
Grafico dei prezzi in tempo reale di Ambire Wallet (WALLET)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!