Ledger's NPM account has been hacked
github.com
Ledger's NPM account has been hacked
1–10 of 130 posts
Re: Ledger's NPM account has been hacked
#2Re: Ledger's NPM account has been hacked
#3I remember buying one in 2019, and shortly thereafter all customer data was dumped on the internet endangering everyone who bought one.
Then after deep diving the tech i threw it in the trash, it seemed like security theatre product.
There's also been so many phishing attempts, fake ledgers sold, bricked ones losing funds, it's total shitshow that ecosystem if you check their subreddit going back in time.
The more you rely on 3. parties, and the more obfuscated your setup is, the more unsafe your data is. I just use isolated cheap laptops and encrypted usb's now.
Re: Ledger's NPM account has been hacked
#4Re: Ledger's NPM account has been hacked
#5NPM forces 2fa, so I’m curious what the scenario was here. Was a committers phone compromised?
Re: Ledger's NPM account has been hacked
#6Re: Ledger's NPM account has been hacked
#7NPM forces 2fa, so I’m curious what the scenario was here. Was a committers phone compromised?
Re: Ledger's NPM account has been hacked
#8Re: Ledger's NPM account has been hacked
#9"The @ledgerhq/connect-kit-loader allows dApps to load Connect Kit at runtime from a CDN so that we can improve the logic and UI without users having to wait for wallet libraries and dApps updating package versions and releasing new builds.
This looks like an extremely dangerous approach now, if I understand it correctly, connect-kit-loader trusts whatever the CDN throws at your dApps. So when connect-kit is comprised, all downstream dApps are automatically exposed."
Re: Ledger's NPM account has been hacked
#10So was there a threat to Ledger users? Elsewhere it's said:
> production build failed