{"id":166755,"date":"2025-09-09T14:00:00","date_gmt":"2025-09-09T14:00:00","guid":{"rendered":"https:\/\/cryptonews.com\/fr\/?p=166755"},"modified":"2025-09-09T14:00:00","modified_gmt":"2025-09-09T14:00:00","slug":"attaque-npm-cryptomonnaies-danger","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/","title":{"rendered":"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM"},"content":{"rendered":"<p>Vos cryptomonnaies peuvent \u00eatre perdues \u00e0 tout moment ? Un hack NPM in\u00e9dit a eu lieu le lundi 8 septembre. Un \u00e9v\u00e8nement qui aurait pu <strong>bouleverser l&#8217;avenir de l&#8217;industrie<\/strong> mais qui se finit plut\u00f4t de la bonne mani\u00e8re. Faisons le point sur une attaque sophistiqu\u00e9e qui a tout de m\u00eame occasionn\u00e9 quelques pertes.<\/p><h2 class=\"wp-block-heading\">Best Wallet : la meilleure solution pour conserver des cryptomonnaies <\/h2><span class=\"replacer\"><\/span><p>Tandis que la communaut\u00e9 des d\u00e9veloppeurs fut confront\u00e9e temporairement \u00e0 un d\u00e9fi avec le hack NPM, cela fait \u00e9merger de nouvelles solutions. <a href=\"https:\/\/cryptonews.com\/fr\/ext\/best-wallet\/\" rel=\" sponsored nofollow\">Best Wallet<\/a> est id\u00e9al dans de telles situations. Une interface intuitive, un haut degr\u00e9 de lisibilit\u00e9 des transactions et une <strong>compatibilit\u00e9 avec plus de 60 blockchains<\/strong>.<\/p><p>Avec son <a href=\"https:\/\/cryptonews.com\/fr\/cryptomonnaie\/acheter-best-wallet-token\/\">jeton natif $BEST<\/a>, toujours disponible en pr\u00e9vente, Best Wallet <strong>dispose d&#8217;un vaste \u00e9cosyst\u00e8m<\/strong>. On y retrouve de nombreuses fonctionnalit\u00e9s : airdrops, launchpad, staking, swap cross-chain et bien plus encore. Avec plusieurs centaines de milliers d&#8217;utilisateurs et un syst\u00e8me de s\u00e9curit\u00e9 perfomant, Best Wallet est une option de choix pour faire face \u00e0 des \u00e9v\u00e8nements futurs similaires.<\/p><p><\/p><div style=\"background: #920047;margin: auto;width: 50%;text-align: center;padding:8px;border-radius:5px;background-image:linear-gradient(107deg,#930046,#59008a);color: white;padding-left: 1em;padding-right: 1em;font-size: 16px\"><a style=\"text-decoration:none;color:white\" href=\"https:\/\/cryptonews.com\/fr\/ext\/bestwalletprevente\/\" target=\"_blank\" rel=\"nofollow noindex\">D\u00e9couvrez la pr\u00e9vente de BEST<\/a><\/div><p><\/p><p class=\"disclaimer-rw\" style=\"text-align: center\"><em>Les crypto-actifs repr\u00e9sentent un investissement risqu\u00e9.<\/em><\/p><h2 class=\"wp-block-heading\">Hack NPM : JavaScript pour cibler les utilisateurs cryptos<\/h2><span class=\"replacer\"><\/span><p>C&#8217;est une attaque d&#8217;une ampleur in\u00e9dite qui a pris place le lundi 8 septembre. Une <strong>attaque de type Supply Chain <\/strong>a pris place. En effet, des utilisateurs malveillants ont int\u00e9gr\u00e9 des malwares dans 18 packages JavaScript, h\u00e9berg\u00e9s sur le registre NPM, qui sont commun\u00e9ment utilis\u00e9s dans l&#8217;industrie crypto (2 milliards de t\u00e9l\u00e9chargements hebdomadaires). <\/p><p>Avec un e-mail de phising, un d\u00e9veloppeur NPM fut compromis, permettant la<strong> publication de versions malveillantes. <\/strong><\/p><figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udea8 There\u2019s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.<br><br>The malicious payload works\u2026<\/p>&mdash; Charles Guillemet (@P3b7_) <a href=\"https:\/\/twitter.com\/P3b7_\/status\/1965094840959410230?ref_src=twsrc%5Etfw\">September 8, 2025<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure><p>Charles Guillemet, CTO de Ledger, a inform\u00e9 tr\u00e8s rapidement la communaut\u00e9 de la situation. Le code inject\u00e9 dans les packages JavaScript permettaient aux attaquants de <strong>manipuler des interactions<\/strong>, notamment avec les portefeuilles, par la modification des adresses cibles, redirigeant les fonds \u00e0 destination des attaquants. <\/p><p><strong>Une initative tr\u00e8s ing\u00e9nieuse<\/strong>, bien que cela fut r\u00e9gl\u00e9 rapidement avec la suppression des versions malveillantes. Heureusement, cette <a href=\"https:\/\/vercel.com\/blog\/critical-npm-supply-chain-attack-response-september-8-2025\" target=\"_blank\" rel=\"noreferrer noopener\">attaque<\/a> fut d\u00e9tect\u00e9e en moins de 5 minutes. Cela aurait pu conduire \u00e0 la parte de plusieurs dizaines de millions de dollars dans l&#8217;industrie. Finalement, moins de 500 dollars de pertes on-chain.<\/p><figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">INTEL: The largest NPM supply chain attack in history has so far netted less than $500 <a href=\"https:\/\/t.co\/unfj6fjEup\">pic.twitter.com\/unfj6fjEup<\/a><\/p>&mdash; Solid Intel \ud83d\udce1 (@solidintel_x) <a href=\"https:\/\/twitter.com\/solidintel_x\/status\/1965374260043821445?ref_src=twsrc%5Etfw\">September 9, 2025<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure><h2 class=\"wp-block-heading\">Modification des usages et prise de conscience : le Web 3 n&#8217;est pas infaillible<\/h2><span class=\"replacer\"><\/span><p>Dans le cadre de cette attaque, ce sont les wallets h\u00e9berg\u00e9s en ligne (sur navigateur) qui \u00e9taient les plus sensibles, les transactions pouvant \u00eatre intercept\u00e9es. Pr\u00e9sent sur de nombreuses blockchains, <strong>certaines victimes ont toutefois eu lieu.<\/strong> Par exemple, la plateforme Swissborg confirme, avec son partenaire, une <a href=\"https:\/\/cryptonews.com\/fr\/news\/swissborg-hack-41-millions-dollars-solana\/\">perte de 41,5 millions de dollars<\/a> dans le cadre du programme Earn. <\/p><p>Dans ce contexte, d\u00e9tenir ses actifs sur un hardware wallet \u00e9tait bien plus s\u00e9curis\u00e9, les fonds hors de port\u00e9e, tout en surveillant ses transactions. Toutefois, avec un CEX, une seule mauvaise manipulation pouvait <strong>rendre l&#8217;ensemble des actifs \u00e0 risque<\/strong>. Dans ce cadre, des recommandations ont \u00e9t\u00e9 publi\u00e9es par Vercel.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"957\" height=\"457\" src=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123032\/Capture-decran-2025-09-09-a-14.30.26.png\" alt=\"\" class=\"wp-image-166798\" srcset=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123032\/Capture-decran-2025-09-09-a-14.30.26.png 957w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123032\/Capture-decran-2025-09-09-a-14.30.26-300x143.png 300w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123032\/Capture-decran-2025-09-09-a-14.30.26-768x367.png 768w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123032\/Capture-decran-2025-09-09-a-14.30.26-130x63.png 130w, https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123032\/Capture-decran-2025-09-09-a-14.30.26-450x215.png 450w\" sizes=\"auto, (max-width: 957px) 100vw, 957px\"><\/figure><p>Ainsi, un tel \u00e9v\u00e8nement pourrait r\u00e9orienter les usages, et faire prendre conscience que le Web 3 n&#8217;est pas un <strong>havre de paix sans failles techniques<\/strong>. Bien au contraire, la d\u00e9centralisation et l&#8217;open-source peuvent augmenter les probabilit\u00e9s de perdre ses fonds malgr\u00e9 de nombreux entreprises d&#8217;audits et une s\u00e9curisation pro-active des protocoles.<\/p><hr class=\"wp-block-separator has-alpha-channel-opacity\"><p class=\"disclaimer-rw\"><em>Les informations pr\u00e9sent\u00e9es dans cet article ne constituent en aucun cas un conseil en investissement. Elles sont fournies \u00e0 des fins exclusivement informatives. Le march\u00e9 des crypto-actifs demeure hautement volatil et comporte des risques significatifs de pertes. Il est recommand\u00e9 aux lecteurs de n\u2019investir que les montants qu\u2019ils peuvent se permettre de perdre, et de proc\u00e9der \u00e0 leurs propres recherches avant toute prise de position sur les march\u00e9s.<\/em><\/p><hr class=\"wp-block-separator has-alpha-channel-opacity\"><p>Pour aller plus loin sur le sujet : <\/p><ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/cryptonews.com\/fr\/news\/ethereum-plafonne-sous-4-400-dollars\/\">Ethereum plafonne sous 4 500 $ : les sorties ETF grippent la dynamique haussi\u00e8re<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/cryptonews.com\/fr\/news\/etf-chainlink-link-grayscale-dossier-sec\/\">ETF Chainlink (LINK) : Grayscale d\u00e9pose un dossier aupr\u00e8s de la SEC<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/cryptonews.com\/fr\/news\/le-kazakhstan-reserve-nationale-crypto-2026\/\">Le Kazakhstan pousse pour une r\u00e9serve nationale de crypto \u00e0 l\u2019horizon 2026<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Vos cryptomonnaies peuvent \u00eatre perdues \u00e0 tout moment ? Un hack NPM in\u00e9dit a eu lieu le lundi 8 septembre. Un \u00e9v\u00e8nement qui aurait pu bouleverser l&#8217;avenir de l&#8217;industrie mais qui se finit plut\u00f4t de la bonne mani\u00e8re. Faisons le point sur une attaque sophistiqu\u00e9e qui a tout de m\u00eame occasionn\u00e9 quelques pertes.Best Wallet : [&hellip;]<\/p>\n","protected":false},"author":594,"featured_media":166800,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2106],"tags":[],"editors":[2550],"sponsored_companies":[],"class_list":["post-166755","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-price-predictions","editors-jurgen-hoffman"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM<\/title>\n<meta name=\"description\" content=\"Attaque majeure sur la supply chain JavaScript. Quelles cons\u00e9quences pour vos cryptos ? Faisons le point sur la situation.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM\" \/>\n<meta property=\"og:description\" content=\"Attaque majeure sur la supply chain JavaScript. Quelles cons\u00e9quences pour vos cryptos ? Faisons le point sur la situation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptonews France\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-09T14:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM\" \/>\n<meta name=\"twitter:description\" content=\"Attaque majeure sur la supply chain JavaScript. Quelles cons\u00e9quences pour vos cryptos ? Faisons le point sur la situation.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM","description":"Attaque majeure sur la supply chain JavaScript. Quelles cons\u00e9quences pour vos cryptos ? Faisons le point sur la situation.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/","og_locale":"fr_FR","og_type":"article","og_title":"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM","og_description":"Attaque majeure sur la supply chain JavaScript. Quelles cons\u00e9quences pour vos cryptos ? Faisons le point sur la situation.","og_url":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/","og_site_name":"Cryptonews France","article_published_time":"2025-09-09T14:00:00+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM","twitter_description":"Attaque majeure sur la supply chain JavaScript. Quelles cons\u00e9quences pour vos cryptos ? Faisons le point sur la situation.","twitter_image":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/"},"author":{"name":"J\u00fcrgen Hoffmann","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/person\/81c8693c469d29b9a4ba777e78fb5b29"},"headline":"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM","datePublished":"2025-09-09T14:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/"},"wordCount":702,"publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg","articleSection":["Pr\u00e9dictions de prix"],"inLanguage":"fr-FR","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/","url":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/","name":"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg","datePublished":"2025-09-09T14:00:00+00:00","description":"Attaque majeure sur la supply chain JavaScript. Quelles cons\u00e9quences pour vos cryptos ? Faisons le point sur la situation.","breadcrumb":{"@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/#primaryimage","url":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg","contentUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2025\/09\/09123758\/1757421477-cryptonews-89.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/fr\/news\/attaque-npm-cryptomonnaies-danger\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Vos cryptomonnaies sont en danger : Supply chain attack du registre NPM"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/fr\/#website","url":"https:\/\/cryptonews.com\/fr\/","name":"Cryptonews","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/fr\/#organization","name":"Cryptonews France","url":"https:\/\/cryptonews.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews France"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/166755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/users\/594"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/comments?post=166755"}],"version-history":[{"count":1,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/166755\/revisions"}],"predecessor-version":[{"id":166799,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/166755\/revisions\/166799"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media\/166800"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media?parent=166755"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/categories?post=166755"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/tags?post=166755"},{"taxonomy":"editors","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/editors?post=166755"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/sponsored_companies?post=166755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}