The Ledger Connect Kit Supply Chain Attack
Updated 5 Oct 2026 · Incident date 14 Dec 2023 · npm
@ledgerhq/connect-kit 1.1.4 -> 1.1.5, 1.1.6, 1.1.7the published dist bundle of @ledgerhq/connect-kit@ledgerhq/connect-kit versions 1.1.5, 1.1.6, and 1.1.7 contained a wallet drainer. The malicious files were live for about five hours on 14 December 2023. Version 1.1.8 is the fixed release.
The attacker phished the npm account of a former Ledger employee. Users who approved transactions in apps that used the library sent funds to the attacker.
What happened
An attacker published three poisoned versions of @ledgerhq/connect-kit to npm after phishing a former employee. Socket reports that the malicious code tricked users into sending funds to the attacker instead of their own wallets. It did this through a rogue WalletConnect project.
The package powers wallet connections for apps such as SushiSwap and Revoke.cash. The malicious code was live for about five hours. Most funds left victim wallets in under two hours. Ledger released the fix within 40 minutes of the alert.
Checkmarx reports that more than $700,000 was stolen. It also notes a useful warning sign. The poisoned npm versions had no matching Git tags or releases in the source repository.
After the incident, Ledger rotated its internal secrets for GitHub publishing and set npm project permissions for the development team to read-only, so that nobody can push packages directly. WalletConnect disabled the rogue project.
Affected versions
- @ledgerhq/connect-kit 1.1.5 (malicious)
- @ledgerhq/connect-kit 1.1.6 (malicious)
- @ledgerhq/connect-kit 1.1.7 (malicious)
- @ledgerhq/connect-kit 1.1.8 (fixed)
- 1.1.4 and earlier are the releases before the attack
Indicators of compromise
- @ledgerhq/connect-kit at version 1.1.5, 1.1.6, or 1.1.7 in
package-lock.json,yarn.lock, ornode_modules. - An npm release with no matching Git tag or release in the source repository.
- Wallet approval requests that route funds through an unknown WalletConnect project.
Neither Socket nor Checkmarx publishes the rogue project ID or the attacker wallet address, so this page does not list them.
How to check
List the installed version of the package with npm. The command does not run the package.
npm ls @ledgerhq/connect-kit
Search lock files in every repository and build output.
grep -rn -A1 '@ledgerhq/connect-kit' package-lock.json yarn.lock pnpm-lock.yaml
What to do now
- Upgrade @ledgerhq/connect-kit to 1.1.8 or later, then rebuild and redeploy every site that bundles it.
- If you ran a site on an affected version on 14 December 2023, tell your users. Ask any who approved a transaction in that period to review their wallets.
- Rotate npm and GitHub publishing credentials. Turn on two-factor authentication for each account that can publish.
- Remove publish rights from former staff.
- Compare each new npm release with a Git tag or release before you trust it.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 40 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED package.json It now reads saved passwords and access keys. It did not before.
Frequently asked questions
Which Ledger Connect Kit versions were malicious?
Versions 1.1.5, 1.1.6, and 1.1.7 of @ledgerhq/connect-kit. Version 1.1.8 is the fixed release.
How did attackers publish the malicious Ledger Connect Kit?
They phished the npm account of a former Ledger employee and published the poisoned versions with it.
How long was the Ledger Connect Kit drainer live?
About five hours. Most funds were drained in under two hours, and Ledger released a fix within 40 minutes of the alert.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.