Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Ledger Connect Kit npm Compromise 2023: How a…
Breach analysis Incident: 14 Dec 2023

Ledger Connect Kit npm Compromise 2023: How a Former Employee’s Unrevoked npm Access Shipped a Wallet Drainer

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
On this page

On 14 December 2023, an attacker published three malicious versions of Ledger Connect Kit, a JavaScript library that many decentralised apps (dApps) load to connect to Ledger hardware wallets, to the npm registry. Ledger says the attacker phished a former employee whose npm access had never been revoked, and used that person's session token, or in another passage of its report an API key tied to the account, to get past two-factor authentication. Versions 1.1.5, 1.1.6 and 1.1.7 carried Angel Drainer, a wallet-draining kit that tricked users into signing transactions sending their crypto to the attacker. The malicious file was reachable for about five hours and funds were drained for under two hours, according to Ledger, which deployed a clean version within 40 minutes of finding out. Ledger later put user losses at about $600,000. Hardware wallets themselves were not compromised: the damage came from a publishing identity that outlived the job it belonged to.

Key takeaways

  • Ledger says a former employee was phished on the morning of 14 December 2023 and that their access to npm "was not properly revoked", leaving a live publishing identity for the Ledger Connect Kit package.
  • The attacker used that access to bypass two-factor authentication and publish versions 1.1.5, 1.1.6 and 1.1.7 with the Angel Drainer wallet drainer, according to Ledger's incident report.
  • Ledger said it was "aware of approximately $600k in assets impacted"; BleepingComputer cited reports of about $680,000. Tether froze the attacker's USDT and WalletConnect disabled the rogue project used to route funds.
  • The compromise is confirmed by Ledger. The malicious code was live for about five hours, with active draining under two hours, and dApps that loaded the affected versions served the drainer to their own users.
  • The identity lesson: offboarding must cover every external publishing identity a person holds, not just the corporate directory, because package registry access is a supply chain credential.

At a glance

OrganisationsLedger (Ledger Connect Kit library); dApps that loaded the library and their users
When14 December 2023, with malicious versions published between 09:49 and 11:37 CET; fixed the same afternoon; Ledger's full report 20 December 2023
AttackerUnidentified attacker using the Angel Drainer malware-as-a-service kit, according to Ledger
Entry pointPhishing of a former Ledger employee whose npm account access had not been revoked
Identities abusedThe former employee's npm publishing access for the Ledger Connect Kit package, used through a session token or an API key associated with the account (Ledger's report uses both terms) to bypass 2FA
ImpactThree malicious package versions with a wallet drainer; about $600,000 in user assets stolen, according to Ledger; malicious file reachable for about five hours
CategoryNHI. Incident class: confirmed NHI breach (former employee's unrevoked npm publishing access used to ship a wallet drainer)

What happened

Ledger Connect Kit is a small library that dApps use to let people connect their Ledger wallets. A release published to npm flowed to the dApps that pulled the library in, and Ledger says the file was also served through a content delivery network, where caching kept the malicious version reachable after the fix.

Ledger's incident report says that on the morning of 14 December 2023 "the attacker phished a former employee to leverage the individual's access on NPMJS." Ledger had removed the person's access to its internal systems, "but unfortunately the former employees' access to NPMJS was not properly revoked." The account was protected by two-factor authentication. Ledger's report says the attacker "worked directly on the session token" and, in another passage, that "the attacker circumvented this security measure by exploiting an API key associated with the former employee's account." Either way, the attacker held a live credential that npm accepted for publishing. Malicious versions 1.1.5, 1.1.6 and 1.1.7 were published at 09:49, 10:44 and 11:37 CET.

The injected code was Angel Drainer, which Ledger describes as "a malware as a service that is specifically designed to craft malicious transactions." It presented users of affected dApps with malicious transactions to sign that sent their funds to the attacker. Ledger spokesperson Phillip Costigan told TechCrunch: "The malicious code used a rogue WalletConnect project to reroute funds to a hacker wallet," and that "the window where funds were drained was limited to a period of less than two hours". Ledger says on-chain funds were split 85% to the attacker and 15% to the Angel Drainer operators.

Ledger says it learned of the attack at 13:45 CET, partly through outreach from the security firm Blockaid, and deployed a genuine fixed version within 40 minutes of becoming aware. BleepingComputer reported that clean version 1.1.8 was uploaded at 2:35 pm CET. WalletConnect disabled the rogue project and, at Ledger's request, Tether froze the attacker's USDT at 14:55 CET. Because of CDN caching the malicious file stayed reachable for about five hours in total. On 20 December Ledger said on X: "We are aware of approximately $600k in assets impacted, stolen from users blind signing on EVM DApps." Ledger also said npm "does not allow multi-authorization or signature verification for automatic publishing", and that it would add controls at the deployment stage and stop offering blind signing.

Timeline

DateEvent
14 December 2023Morning: a former Ledger employee is phished; the attacker uses their still-active npm access to bypass 2FA, according to Ledger.
14 December 202309:49, 10:44 and 11:37 CET: malicious Ledger Connect Kit versions 1.1.5, 1.1.6 and 1.1.7 are published to npm.
14 December 202313:45 CET: Ledger becomes aware, partly through Blockaid; a genuine version is deployed within 40 minutes, Ledger says.
14 December 202314:55 CET: Tether freezes the attacker's USDT at Ledger's request; WalletConnect disables the rogue project. TechCrunch and BleepingComputer report the attack.
20 December 2023Ledger publishes its incident report and estimates about $600,000 in user assets stolen.

How it happened: the identity attack path

  1. Offboarding gap. When the employee left Ledger, their internal accounts were disabled but their npm access to the Ledger Connect Kit package remained, a live publishing identity with no current owner inside the company.
  2. Phishing the leaver. The attacker phished the former employee and gained use of that npm access.
  3. MFA bypassed with a live token. Instead of logging in afresh, the attacker used a session token, or an API key tied to the account, that npm accepted without a second factor.
  4. Malicious publish. Three new versions carrying the Angel Drainer kit were published to npm and picked up by dApps that used the library.
  5. Funds drained. Users of affected dApps signed malicious transactions that sent assets to the attacker through a rogue WalletConnect project, until the clean release, Tether's freeze and WalletConnect's action stopped it.

Impact

  • Confirmed by Ledger: three malicious versions of Ledger Connect Kit were published; about $600,000 in assets were stolen from users who blind signed transactions on EVM dApps; the drainer was active for under two hours and the file reachable for about five.
  • Reported elsewhere: BleepingComputer cited reports putting losses at about $680,000; TechCrunch reported that more than $600,000 had collected in the hacker's wallet, according to the investigator ZachXBT.
  • Not affected: Ledger hardware devices were not the attack vector; the damage came through third-party dApps that loaded the library.
  • Wider: one library compromise put the users of many unrelated dApps at risk at once, which is what makes package publishing access so valuable to attackers.

What this means for NHI governance

A package registry account that can publish a widely used library is a machine-scale identity, even when it is registered to a person. Ledger's own systems were not breached. What failed was the lifecycle of one external identity: a former employee's npm access, with a token that could get past 2FA, outlived their employment. Once phished, it gave an attacker the right to ship code to every site that trusted the package.

The general lesson is that offboarding has to reach beyond the corporate directory to registries, cloud consoles, SaaS tools and code hosts where people hold tokens on the company's behalf. Publishing should rely on organisation-owned, scoped and short-lived credentials, ideally issued to a build pipeline rather than a person, with a second approval for releases. Our Joiner-Mover-Leaver Guide and CI/CD Pipeline Identity Security Guide cover these controls. The same attack pattern appears in the Lottie Player npm compromise of 2024 and the @solana/web3.js compromise.

Recommendations

  • Revoke every external publishing identity when someone leaves. Keep an inventory of who can publish to npm, PyPI and other registries for the organisation, and remove access and revoke tokens on the leaving date. See our Joiner-Mover-Leaver Guide.
  • Publish from pipelines, not personal accounts. Use trusted publishing or organisation-owned, scoped and short-lived tokens issued to a build system, so no individual's account can ship a release on its own. See our CI/CD Pipeline Identity Security Guide.
  • Treat session and API tokens as credentials that bypass MFA. Expire them quickly, bind them where possible and revoke them on any sign of phishing. See our Token and Session Security Guide.
  • Require a second approval for releases. Ledger noted npm lacked multi-party authorisation for automatic publishing; add it in your own release process with signed artefacts and provenance.
  • Pin and verify dependencies in production sites. Do not load the latest version of a library from a CDN at run time; pin versions and use subresource integrity checks.
  • Monitor your packages for unexpected releases. Alert on new versions published outside the normal pipeline so that a rogue release is caught in minutes. See the Leaked Credential Response Playbook.

Frequently asked questions

What happened in the Ledger Connect Kit hack?

On 14 December 2023 an attacker published three malicious versions of Ledger Connect Kit to npm after phishing a former Ledger employee whose npm access had not been revoked. The versions carried the Angel Drainer kit, which tricked users of dApps into signing transactions that drained their wallets. Ledger estimated losses at about $600,000.

How did the attacker bypass two-factor authentication on npm?

According to Ledger's incident report, the attacker did not need to pass a fresh login. It used a session token, or an API key associated with the former employee's npm account (the report uses both terms), which npm accepted for publishing without a second factor.

Were Ledger hardware wallets compromised?

No. The attack targeted a JavaScript library used by third-party dApps, not Ledger's devices. Users lost funds when they signed malicious transactions shown by affected dApps. Ledger has since pushed clear signing and said it will stop offering blind signing.

Lottie Player npm compromise 2024 · @solana/web3.js npm compromise 2024 · Shai-Hulud npm worm 2025 · Joiner-Mover-Leaver Guide · CI/CD Pipeline Identity Security Guide

How NHI Mgmt Group can help

Registry accounts, publishing tokens and session tokens held by staff are among the least visible identities in a software supply chain. We help organisations inventory who can publish their code, move releases onto pipeline identities and close the offboarding gaps that let a former employee's access outlive their job. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org