Watch Out: Virus Detected in Software Downloaded Over 1 Billion Times, Theft Alert for Cryptocurrency Owners
Ledger's CTO, Charles Guillemet, warned of a large-scale cyberattack that could directly impact the cryptocurrency market.
“A respected developer's NPM account was compromised, and packages distributed through that account have been downloaded over 1 billion times. This puts the entire JavaScript ecosystem at risk,” Guillemet said.
According to details of the attack, the malware attempts to steal users' funds by silently changing crypto addresses. This method, known as a “crypto-clipper,” specifically targets software wallet users.
Guillemet argued that hardware wallet users are safe if they carefully check addresses before signing transactions, but software wallet users should avoid on-chain transactions for now. It's also unclear whether attackers are directly stealing seed phrases from software wallets.
Here are some suggestions for developers:
- Fix the error-ex package to version 1.3.2 (using the overrides property in package.json).
- Prefer npm ci command instead of npm install in your build processes.
- Be sure to check the addresses before making any transactions.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Wall Street interprets the Federal Reserve decision as more dovish than expected
The market originally expected a "hawkish rate cut" from the Federal Reserve, but in reality, there were no additional dissenters, no higher dot plot, and the anticipated tough stance from Powell did not materialize.

The Federal Reserve cuts rates again but divisions deepen, next year's path may become more conservative
Although this rate cut was as expected, there was an unusual split within the Federal Reserve, and it hinted at a possible prolonged pause in the future. At the same time, the Fed is stabilizing year-end liquidity by purchasing short-term bonds.

Betting on LUNA: $1.8 billion is being wagered on Do Kwon's prison sentence
The surge in LUNA’s price and huge trading volume are not a result of fundamental recovery, but rather the market betting with real money on how long Do Kwon will be sentenced on the eve of his sentencing.

What is the overseas crypto community talking about today?
What have foreigners been most concerned about in the past 24 hours?

