Ledger CTO Charles Guillemet posted, "A large-scale supply chain attack is currently underway: the NPM account of a well-known developer has been compromised. The affected packages have been downloaded over 1 billion times, which means the entire JavaScript ecosystem may be at risk. The malicious code works by silently tampering with cryptocurrency addresses in the background to steal funds. If you use a hardware wallet, please carefully check every signed transaction and you will be safe. If you do not use a hardware wallet, please avoid any on-chain transactions for the time being. It is not clear whether the attacker has directly stolen the mnemonic phrase of the software wallet. If you use a Ledger or other hardware wallet that supports clear signatures, you are not affected. My previous tweet was a reminder: users who do not use hardware wallets that support clear signatures are at risk. Be sure to carefully check every transaction before signing. For more details, please see the detailed report."