BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home BUSINESS

Ledger CTO Warns of Large-Scale Crypto Hack Attack: What You Need to Do

Charles Ghanime by Charles Ghanime
September 8, 2025
in BUSINESS, CRYPTO, FINANCE, OPINION
Share on XShare in TelegramShare on Reddit
  • A major npm maintainer’s account was hacked, pushing malicious updates to libraries with billions of downloads.
  • The malware swaps crypto addresses in transactions, aiming to divert funds to attackers.
  • Users should audit dependencies, pin safe versions, and verify all wallet transactions (hardware wallets remain safest).

A prominent npm maintainer’s account (known as Qix) was hijacked, leading to malicious updates in widely used packages such as chalk, strip-ansi, ansi-styles, and debug. These libraries collectively see billions of downloads each week, making this one of the most serious supply-chain breaches the JavaScript ecosystem has ever faced. While npm security teams are removing compromised versions, dangerous releases may still exist in cached lockfiles or indirect dependencies.

🚨 WARNING: LEDGER EXEC WARNS TO NOT DO ANY BLOCKCHAIN TRANSACTIOSN DUE TO "LARGE SCALE" CRYPTO HACK IN JAVASCRIPT pic.twitter.com/ETprvJJXZD

— BlockNews (@blocknewsdotcom) September 8, 2025

Why it matters

These libraries aren’t obscure—they are foundational building blocks inside thousands of apps, frameworks, and developer tools. When something this deep in the ecosystem is compromised, the impact cascades across startups, Fortune 500 companies, and open-source projects worldwide. The sheer scale explains why security leaders are sounding alarms beyond the developer community.

What the malware does

Researchers have identified the attack as a crypto-clipper. Its function is deceptively simple: when someone tries to send cryptocurrency, the malware silently replaces the destination address with one controlled by the attacker. To the user, nothing looks unusual until funds are gone. It doesn’t target blockchains themselves—it tricks people into signing transactions to the wrong account.

Urgent warnings for crypto users

In a striking development, a Ledger executive publicly warned users not to conduct any blockchain transactions at all while the hack is ongoing, calling it a “large-scale” crypto security incident tied to the compromised JavaScript packages. This warning highlights the seriousness of the attack, especially for those relying on browser wallets or software-based signing.

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.

The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

What you should do now

  1. Audit and pin. Lock dependencies to the last known-safe versions and rebuild from scratch.
  2. Verify every transaction. Hardware wallets remain the safest option—always confirm addresses directly on the device.
  3. Pause if possible. If you rely on software wallets, consider delaying on-chain activity until the situation stabilizes.

What’s next

Expect continuous updates from npm, maintainers, and security firms as remediation advice is issued. This attack follows a wave of recent npm compromises, showing that attackers are deliberately targeting open-source infrastructure. Developers are urged to enable 2FA on npm accounts, rotate credentials, and add CI checks to flag suspicious code changes.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: cryptoHackLedgernpmQixsecurity
Tweet6ShareShare
Charles Ghanime

Charles Ghanime

Charles has been deeply involved in Web3 since mining Ethereum back in 2014, and today he holds $HYPE, $BTC, $ETH, $APTOS, $DOT, and $SUI. He has collaborated with top KOLs to create impactful content, analyze market trends, and provide data-driven insights. His experience spans think tank work with leading blockchain projects, high-level marketing collaborations with global tech leaders, and publishing over 600 in-depth analyses on blockchain projects, positioning him as a trusted voice in the industry.

DON'T MISS THESE! HOT OFF THE PRESS

Mt. Gox Moves Bitcoin Again – Here Is Why Crypto Markets Are Watching Closely
BITCOIN

Mt. Gox Moves Bitcoin Again – Here Is Why Crypto Markets Are Watching Closely

March 23, 2026
Strategy Adds More Bitcoin Despite Losses – Here Is Why Crypto Accumulation Continues
BITCOIN

Strategy Adds More Bitcoin Despite Losses – Here Is Why Crypto Accumulation Continues

March 23, 2026
Cardano’s Next Upgrade Isn’t Just Technical, It’s a Quiet Setup for Institutional Relevance
CARDANO

Cardano’s Next Upgrade Isn’t Just Technical, It’s a Quiet Setup for Institutional Relevance

March 23, 2026
SEC Reclassifies Crypto as Digital Commodities, Quietly Reshaping Institutional Capital Flows Across Markets
CRYPTO

SEC Reclassifies Crypto as Digital Commodities, Quietly Reshaping Institutional Capital Flows Across Markets

March 23, 2026
Bitcoin Crypto Jumps on Iran Strike Pause – Here Is Why Markets Are Rebounding
BITCOIN

Bitcoin Crypto Jumps on Iran Strike Pause – Here Is Why Markets Are Rebounding

March 23, 2026
Aster Crypto Faces Critical Support Test Amid Weak Momentum – Here Is the Outlook
CRYPTO

Aster Crypto Faces Critical Support Test Amid Weak Momentum – Here Is the Outlook

March 22, 2026
Load More

Related News

Mt. Gox Moves Bitcoin Again – Here Is Why Crypto Markets Are Watching Closely

Mt. Gox Moves Bitcoin Again – Here Is Why Crypto Markets Are Watching Closely

March 23, 2026
Strategy Adds More Bitcoin Despite Losses – Here Is Why Crypto Accumulation Continues

Strategy Adds More Bitcoin Despite Losses – Here Is Why Crypto Accumulation Continues

March 23, 2026
Cardano’s Next Upgrade Isn’t Just Technical, It’s a Quiet Setup for Institutional Relevance

Cardano’s Next Upgrade Isn’t Just Technical, It’s a Quiet Setup for Institutional Relevance

March 23, 2026
SEC Reclassifies Crypto as Digital Commodities, Quietly Reshaping Institutional Capital Flows Across Markets

SEC Reclassifies Crypto as Digital Commodities, Quietly Reshaping Institutional Capital Flows Across Markets

March 23, 2026
Bitcoin Crypto Jumps on Iran Strike Pause – Here Is Why Markets Are Rebounding

Bitcoin Crypto Jumps on Iran Strike Pause – Here Is Why Markets Are Rebounding

March 23, 2026
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews