{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:19:32.012Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Ledger Connect Kit poisoned after a former employee's npm account was phished","date":"2023-12-14","date_precision":"day","victim_org":"Ledger SAS","sector":"Cryptocurrency","country":"France","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Supply Chain Compromise","Cryptocurrency Theft","Credential Theft"],"loss_usd":600000,"loss_note":"Commonly reported as roughly $600,000 drained; CoinDesk cited an on-chain figure of about $484,000 in the immediate aftermath. Ledger said proceeds were split 85/15 between the attacker and the Angel Drainer service.","records_affected":null,"threat_actor":"Operator using the Angel Drainer drainer-as-a-service","summary":"On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.","how_it_worked":"The former employee's access to Ledger's internal systems had been revoked at offboarding, but their npmjs publishing rights had not been manually removed. A phishing attack captured a valid session token rather than a password, which sidestepped the account's 2FA entirely and let the attacker publish new Connect Kit versions. Those versions injected the Angel Drainer script into any decentralised application that loaded the library, prompting users to sign transactions that transferred their assets to the attacker. Ledger shipped a clean version within about 40 minutes of learning of the compromise, but CDN caching kept the poisoned file reachable for roughly five hours in total.","lessons":"Offboarding must enumerate and revoke package-registry and other third-party publishing rights, and releases to public package registries should require hardware-key-backed signing plus a second approver rather than a single session.","confidence":"Confirmed","sources":[{"title":"Security Incident Report","url":"https://www.ledger.com/blog/security-incident-report","publisher":"Ledger"},{"title":"Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft","url":"https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html","publisher":"The Hacker News"},{"title":"Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code","publisher":"CoinDesk"}],"entry_type":"incident","slug":"2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-ledger-connect-kit-poisoned-after-a-former-employee-s-npm-account-was-ph"}]}