The Ledger Connect Kit Supply Chain Attack

Updated 5 Oct 2026 · Incident date 14 Dec 2023 · npm

Package@ledgerhq/connect-kit 1.1.4 -> 1.1.5, 1.1.6, 1.1.7
Filethe published dist bundle of @ledgerhq/connect-kit

@ledgerhq/connect-kit versions 1.1.5, 1.1.6, and 1.1.7 contained a wallet drainer. The malicious files were live for about five hours on 14 December 2023. Version 1.1.8 is the fixed release.

The attacker phished the npm account of a former Ledger employee. Users who approved transactions in apps that used the library sent funds to the attacker.

What happened

An attacker published three poisoned versions of @ledgerhq/connect-kit to npm after phishing a former employee. Socket reports that the malicious code tricked users into sending funds to the attacker instead of their own wallets. It did this through a rogue WalletConnect project.

The package powers wallet connections for apps such as SushiSwap and Revoke.cash. The malicious code was live for about five hours. Most funds left victim wallets in under two hours. Ledger released the fix within 40 minutes of the alert.

Checkmarx reports that more than $700,000 was stolen. It also notes a useful warning sign. The poisoned npm versions had no matching Git tags or releases in the source repository.

After the incident, Ledger rotated its internal secrets for GitHub publishing and set npm project permissions for the development team to read-only, so that nobody can push packages directly. WalletConnect disabled the rogue project.

Affected versions

Indicators of compromise

Neither Socket nor Checkmarx publishes the rogue project ID or the attacker wallet address, so this page does not list them.

How to check

List the installed version of the package with npm. The command does not run the package.

npm ls @ledgerhq/connect-kit

Search lock files in every repository and build output.

grep -rn -A1 '@ledgerhq/connect-kit' package-lock.json yarn.lock pnpm-lock.yaml

What to do now

  1. Upgrade @ledgerhq/connect-kit to 1.1.8 or later, then rebuild and redeploy every site that bundles it.
  2. If you ran a site on an affected version on 14 December 2023, tell your users. Ask any who approved a transaction in that period to review their wallets.
  3. Rotate npm and GitHub publishing credentials. Turn on two-factor authentication for each account that can publish.
  4. Remove publish rights from former staff.
  5. Compare each new npm release with a Git tag or release before you trust it.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old @ledgerhq/connect-kit-1.1.4 --new @ledgerhq/connect-kit-1.1.5
files scanned: 40

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.json
           It now reads saved passwords and access keys. It did not before.

Frequently asked questions

Which Ledger Connect Kit versions were malicious?

Versions 1.1.5, 1.1.6, and 1.1.7 of @ledgerhq/connect-kit. Version 1.1.8 is the fixed release.

How did attackers publish the malicious Ledger Connect Kit?

They phished the npm account of a former Ledger employee and published the poisoned versions with it.

How long was the Ledger Connect Kit drainer live?

About five hours. Most funds were drained in under two hours, and Ledger released a fix within 40 minutes of the alert.

Sources

  1. socket.dev/blog/ledger-connect-kit-supply-chain-attack-wallet-drainer
  2. checkmarx.com/blog/npm-account-takeover-results-in-crypto-supply-chain-attack/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free