Ledgers CTO says a major supply-chain attack on the Node Package Manager ecosystem luckily failed with almost no victims, thanks to rapid detection. The incident, which started with a phishing campaign, allowed hackers to push malicious JavaScript package updates. The attack targeted Ethereum, Solana, and other chains, but implementation errors led to a swift discovery. Although the immediate danger has passed, the threat remains, prompting users to use hardware wallets and clear signing protections. With many in the crypto industry spared, this serves as a stark reminder of the power and increasing threat of software supply chain compromises.
Read more