Crypto Fetchs
  • Directory
  • Coins
    • Bitcoin
    • Dogecoin
    • Ethereum
    • Litecoin
    • Ripple
    • Tron
    • NFT
  • News
  • Blockchain
  • Slot
  • Casino
  • Submit PR
What's Hot

OpenLedger Surged 200% Today- Here’s Why the Rally Ignited

09/09/2025

Earn $60,000 USD Per Day And Withdraw Cash At Any Time

09/09/2025

npm “debug” Attack Fails, Ledger CTO Confirms Minimal Impact

09/09/2025
  • Terms & Conditions
  • Contact
  • Privacy Policy
  • DMCA
Crypto Fetchs
  • Directory
  • Coins
    1. Bitcoin
    2. Dogecoin
    3. Ethereum
    4. Litecoin
    5. Ripple
    6. Tron
    7. NFT
    8. View All

    OpenLedger Surged 200% Today- Here’s Why the Rally Ignited

    09/09/2025

    OKB Climbs Past $200 Mark Amid Growing Momentum

    08/22/2025

    MARA Grows Hashrate, Reaches 50k Bitcoin & Plans Expansion

    08/04/2025

    Ethereum Nearing a Main Breakout as On-Chain Metrics Hit Report Highs

    07/17/2025

    npm “debug” Attack Fails, Ledger CTO Confirms Minimal Impact

    09/09/2025

    Pudgy Penguins, Blur Market Drop Cast Doubt on PENGU ETF

    08/30/2025

    Circle’s Compliance Claims Challenged by ZachXBT on X

    08/20/2025

    Canaan Mined 89 BTC in July Amid Strategic Global Shift

    08/10/2025

    Ethereum’s Battle for Restoration: Can ETH Keep away from Breaking Under $2,695?

    02/04/2025

    Ethereum Basis’s Gross sales Proceed to Predict Market Tops, Sale Precedes 17% Drop

    12/20/2024

    $10.8B Crypto Choices Expiry Triggers Market Volatility

    11/29/2024

    Ethereum Worth Evaluation: Is This Remaining Pullback Earlier than ETH Breaks $4000?

    11/27/2024

    Backpack Exchange Launches Daily Proof of Reserves

    08/31/2025

    Futu Securities Brings Solana Retail Trading to Hong Kong

    08/15/2025

    eToro to Introduce Tokenized US shares and ETFs on Ethereum

    07/30/2025

    Nemo Cash Expands Globally with Native Entry & AI Instruments

    07/14/2025

    From Crash to Comeback: Can XRP Flip $3.50?

    02/04/2025

    Ripple Will increase RLUSD Testing Forward of Stablecoin Launch: Studies

    12/05/2024

    Can Ripple Worth Hit $3 Amid Report of Rlusd Launching Right now

    12/05/2024

    XRP Worth Goal $2 Breakout with this Bullish Sample

    11/27/2024

    Tron (TRX) Surges to 6-Yr Excessive, Eyes $0.48 All-Time

    12/06/2024

    Justin Solar Cryptic Put up About TRX Future Mimic MicroStrategy

    12/05/2024

    H.E. Justin Solar, the founding father of TRON Basis, joins crypto’s elite on the International Blockchain Present hosted by VAP Group

    11/20/2024

    Justin Solar to Grace Dubai World Blockchain Present in December

    10/08/2024

    Blur NFT Market Removes Third Social gathering Flags

    11/30/2023

    US Decide Guidelines Towards NBA Prime Shot; What Does It Imply For NFTs?

    11/30/2023

    Largest NFT Dump Ever; NFT Market To Crash?

    11/29/2023

    NFT Market Blur Surpasses OpenSea, However For How Lengthy?

    11/29/2023

    OpenLedger Surged 200% Today- Here’s Why the Rally Ignited

    09/09/2025

    Earn $60,000 USD Per Day And Withdraw Cash At Any Time

    09/09/2025

    npm “debug” Attack Fails, Ledger CTO Confirms Minimal Impact

    09/09/2025

    House Of Doge And Bitstamp By Robinhood Announce Strategic Partnership For NYSE:ZONE Treasury

    09/09/2025
  • News

    Earn $60,000 USD Per Day And Withdraw Cash At Any Time

    09/09/2025

    House Of Doge And Bitstamp By Robinhood Announce Strategic Partnership For NYSE:ZONE Treasury

    09/09/2025

    Dogecoin Is Rising! Use Dogecoin (DOGE) To Start A Bitcoin Mining Rig And Earn $5,000 A Day.

    09/09/2025

    Bybit’s WSOT Achieves New GUINNESS WORLD RECORDS™ Title With Highest Number Of Online Trading Participants In A Day

    09/08/2025

    Airdrop Points Stage 2 Live, TGE Countdown Begins

    09/08/2025
  • Blockchain

    Binance Uncovers North Korean Crypto Hacking Campaign

    09/04/2025

    Binance, TRM Labs Unite to Launch Beacon Crime Network

    08/21/2025

    Crypto Beast Returns After $ALT Crash, ZachXBT Probes

    08/07/2025

    PENGU Surges to $0.035 as Korean Whales Accumulate — Pullback Forward?

    07/24/2025

    Nemo Cash Rolls Out International Multi-Asset Investing

    07/10/2025
  • Slot
  • Casino
  • Submit PR
Crypto Fetchs
Home»Coins»Dogecoin»npm “debug” Attack Fails, Ledger CTO Confirms Minimal Impact
Dogecoin

npm “debug” Attack Fails, Ledger CTO Confirms Minimal Impact

adminBy admin09/09/2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Key Highlights: 

  • A major supply chain attack compromised npm packages such as “debug” and “chalk” that are widely used by JavaScript and EthereumJS projects. 
  • Attackers injected malicious code that silently swapped cryptocurrency addresses during transactions. 
  • The attack failed due to coding errors. 

A huge supply chain attack targeting the widely used JavaScript package “debug” (a tool that developers use to log information and troubleshooting apps), was revealed today, September 9, 2025. In this hack, instead of attacking any of the individual projects, hackers managed to compromise this tool which allows malicious code to spread wherever it was installed. Since Ethereum JS libraries and a lot of other projects mainly rely on “debug,” the risk of data theft or deep breaches was significant.

The attack was disclosed on the project’s GitHub issue tracker, where maintainers confirmed that attackers had gained access to publishing credentials. Ledger’s CTO, Charles Guillemet, had posted about this threat yesterday on X and tried to warn users. However, the CTO has now confirmed that the update was quickly detected and the number of victims was minimal because the flawed code caused crashes in CI/CD pipelines, raising red flags early on.

npm “debug” package attack failed

What Happened?

On September 9, 2025, it has been revealed by the security experts that hackers managed to break into the NPM account of a trusted developer (Josh Junon) and pushed out a fake update (v4.4.2) of the popular “debug” package. This tool or package is used in the JavaScript world and EthereumJS libraries a little too much, with over 2 billion weekly downloads, so the attack had the capacity to spread to many apps and systems.

The malicious code had been designed here in such a way that it could secretly swap out real cryptocurrency wallet addresses with the attacker’s own, stealing funds without the users noticing. Since most of the companies that use open-source tools like “debug” without questioning them, a single poisoned update could have spread like a wildfire. But in practice, the attackers’ implementation mistakes caused failure that made detection far easier. This led to limited spread and prevented widespread theft.

How Did the Attack Work?

As mentioned above, the attackers compromised developer’s NPM credentials and pushed a malicious update of the “debug’ package. What the developer did not know was, there was a hidden function that secretly replaced legitimate crypto wallet addresses with the ones controlled by the hackers. Whenever apps using this package generated blockchain transactions, the funds were redirected without the users ever noticing, but because the update crashed pipelines, the attempt backfired and was stopped early.

Could It Get Worse?

Even though this attack failed, it shows how risky the situation would have been if the CI/CD pipelines had not crashed. Poisoned updates could have acted like Trojan horses and they would have embedded themselves into various projects. If this attack was executed with more precision, it would have affected financial apps, exchanges and even non-crypto platforms that depend on the same tools.

Ledger CTO had emphasized in this X post, users of hardware wallets with clear transaction signing remain protected, as they can verify details before signing and prevent silent address swaps.

Precautions to Take Immediately

  • Make sure that you run npm ls debug in your project’s directory and if you happen to see version 4.4.2 installed, remove it immediately and do a clean reinstall from a trusted source.
  • If you are not using a hardware wallet with clear transaction signing, try not to carry out any blockchain transactions until this threat is fully mitigated.
  • Hardware wallets as mentioned by Ledger CTO provide a safety layer which requires manual approval of transaction details so one can easily spot unauthorized address changes.
  • Make sure that your verify the recipient address on transaction confirmation screens before signing.
  • Follow official repos, npm advisories and reliable security channels for updates on the incident.

Also Read: OpenLedger (OPEN) Surged 200% Today- Here’s Why the Rally Ignited

 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin

Related Posts

Pudgy Penguins, Blur Market Drop Cast Doubt on PENGU ETF

08/30/2025

Circle’s Compliance Claims Challenged by ZachXBT on X

08/20/2025

Canaan Mined 89 BTC in July Amid Strategic Global Shift

08/10/2025

Hyperliquid Fixes Buying and selling Outage after Technical Disruption

07/31/2025
Add A Comment

Comments are closed.

  • POPULAR POSTS

OpenLedger Surged 200% Today- Here’s Why the Rally Ignited

09/09/2025

Ethereum Holds Potential to Hit $5k Regardless of Slight Decline

05/01/2022

Litecoin Faces Little Resistance; Will LTC Flip Bullish Quickly?

05/01/2022

Consolidating for the Final Ten Days!

05/01/2022

Pocket Worlds is Launching First-Ever Metaverse Subset

05/01/2022

TRON Value Falls Under $0.030 After Spurring to $0.039

05/01/2022

Dogecoin Breaks Out however Nonetheless Faces Resistance at 200 DMA!

05/01/2022

Bitcoin Struggles To Maintain $40K Whereas Crypto Observe US Shares

05/01/2022

Ethereum Trades Under $3,000 Help, Why Is ETH Falling Since November?

05/01/2022

The Litecoin Basis and Atari Energy Up.

05/01/2022

Crypto Fetchs is your source for the serious crypto currency news. This website is crafted specifically to for crazy and hot crypto news.

Contact Us : Partner(@)Cryptofetchs.com

TOP INSIGHT

R0AR Lists On BitMart: $1R0R Makes CEX Debut

06/23/2025

$1.1M Polymarket Wager on Bitcoin Value Hanging $70K Reviewed

07/29/2024

Pear Protocol Goes Reside With Hyperliquid Integration And Declares $4.1M Strategic Spherical Led By Fort Island Ventures

07/28/2025
Crypto News

Why Did The Bitcoin Worth Fall Beneath $41,000?

01/19/2024

Binance CEO Particulars Prediction, Says Crypto Change About To Reinvent Itself With New Company Construction: Report

11/27/2023

Bitcoin Approaches $100K As Reserves On Exchanges Decline

11/19/2024

Type above and press Enter to search. Press Esc to cancel.