Ace quick missions & earn crypto rewards while gaining real-world Web3 skills. Participate Now! 🔥
Key Takeaways
Ace quick missions & earn crypto rewards while gaining real-world Web3 skills. Participate Now! 🔥
Charles Guillemet, Chief Technology Officer at Ledger, pointed to a recent Node Package Manager (NPM) library attack as a reminder of the risks tied to software wallets and crypto exchanges.
He warned that funds stored on these platforms could be lost through a single line of compromised code. According to Guillemet, software-based systems remain vulnerable to supply chain attacks, where malicious updates enter through trusted tools.
The breach began when attackers sent a phishing email disguised as a message from NPM support. This led to stolen developer credentials, which were used to publish altered versions of used packages such as chalk, debug, and strip-ansi.
Did you know?
Subscribe - We publish new crypto explainer videos every week!
What Does Staking Mean in Crypto? (Easily Explained!)
This code worked by switching out wallet addresses in network traffic. When an app communicated with a blockchain, the malicious code would replace the destination address with one controlled by the attacker.
Bitcoin
Anatoly Makosov, CTO of The Open Network (TON), explained that the attackers tampered with specific releases, 18 versions in total. He noted that apps were at the highest risk if they integrated the affected packages within hours of their release or if they used systems that automatically update dependencies.
Makosov encouraged developers to check whether these versions were present. He also shared a checklist for developers to help identify whether their applications were impacted.
If any of the 18 compromised library versions were in use, the project should be treated as affected.
Lucija Valentić at ReversingLabs recently reported that hackers discovered a new method for spreading malicious software. How? Read the full story.
To ensure the highest level of accuracy & most up-to-date information, BitDegree.org is regularly audited & fact-checked by following strict editorial guidelines & review methodology.
Carefully selected industry experts contribute their real-life experience & expertise to BitDegree's content. Our extensive Web3 Expert Network is compiled of professionals from leading companies, research organizations and academia.