Crypto wallet manufacturer Ledger has confirmed an exploit that led it to warn users to “stop using dapps” started because a former employee fell for a phishing scam.
The former employee’s name and email address showed up in the compromised code. Initially the crypto community took it to mean that the developer himself was responsible for the exploit, but Ledger later confirmed the attack began because “a former Ledger employee fell victim to a phishing attack.”
The attacker was able to gain access to the former employee’s NPMJS account—a package manager for the JavaScript programming language. Packages are libraries that developers can use to build projects, rather than coding everything from scratch. In the Web3 community, developers use packages to make their decentralized apps accessible from different wallets.
Once the exploiter had access to NPMJS, they pushed a malicious version of the Ledger Connect Kit. Any project that was using Connect Kit would have contained malicious code that could reroute a users’ funds to a hacker wallet. The impacted versions of the Connect Kit are 1.1.5, 1.1.6, and 1.1.7—all of which have since been removed from the Ledger’s NPM page.
Go to Source to See Full Article
Author: Stacy Elliott
Tip BTC Newswire with Cryptocurrency