đš Not just Ledger.
A supply chain attack hit NPM packages with 1B+ weekly downloads â used by wallets, dapps & exchanges.
Malware swaps $BTC , $ETH , $SOL , $TRX, $LTC, $BCH addresses + hijacks wallet txs.
If your app uses chalk, strip-ansi, color-convert â youâre exposed.
đ Who could be affected?
These libraries arenât crypto-specific â theyâre core Node.js utilities buried in dependency trees. That means many wallets, payment services, and infra tools may have been exposed:
Wallets:
MetaMask (via CLI / tooling deps)
Phantom (JS-heavy codebase)
Rainbow, Zerion, Frame (depend on Node/NPM pipelines)
Crypto Payment / Infra Services:
Coinbase Wallet & Commerce
Binance Pay
Trust Wallet (uses Node.js in build processes)
Ledger Live desktop (bundles JS libraries)
Alchemy, Infura, Thirdweb (dev SDKs rely on these utils)
DeFi / Web3 apps:
Uniswap Interface, Aave, OpenSea frontend stacks (heavily JS/NPM)
Many dashboards (Zapper, DeBank, Zerion)
đ The danger is indirect: even if your wallet/app didnât directly use the infected package, its dependencies may have pulled them in automatically.
â ïž This is why itâs scary:
A malicious patch version silently spread through the entire JavaScript supply chain, meaning even apps that never touched crypto explicitly could still ship code that steals crypto.
A supply chain attack hit NPM packages with 1B+ weekly downloads â used by wallets, dapps & exchanges.
Malware swaps $BTC , $ETH , $SOL , $TRX, $LTC, $BCH addresses + hijacks wallet txs.
If your app uses chalk, strip-ansi, color-convert â youâre exposed.
đ Who could be affected?
These libraries arenât crypto-specific â theyâre core Node.js utilities buried in dependency trees. That means many wallets, payment services, and infra tools may have been exposed:
Wallets:
MetaMask (via CLI / tooling deps)
Phantom (JS-heavy codebase)
Rainbow, Zerion, Frame (depend on Node/NPM pipelines)
Crypto Payment / Infra Services:
Coinbase Wallet & Commerce
Binance Pay
Trust Wallet (uses Node.js in build processes)
Ledger Live desktop (bundles JS libraries)
Alchemy, Infura, Thirdweb (dev SDKs rely on these utils)
DeFi / Web3 apps:
Uniswap Interface, Aave, OpenSea frontend stacks (heavily JS/NPM)
Many dashboards (Zapper, DeBank, Zerion)
đ The danger is indirect: even if your wallet/app didnât directly use the infected package, its dependencies may have pulled them in automatically.
â ïž This is why itâs scary:
A malicious patch version silently spread through the entire JavaScript supply chain, meaning even apps that never touched crypto explicitly could still ship code that steals crypto.