@ledgerhq/connect-kitnpm
- latest 1.1.12
- licence MIT
- checked yesterday
- registry ↗
- repository ↗
Signals · last 1 check
State history 1
| When | Change |
|---|---|
| 2026-09-03 | first verdict: unknown |
Supply-chain history 1
-
account hijacked 2023-12 1.1.5, 1.1.6, 1.1.7
A former employee was phished and the npm account used to publish versions carrying a wallet drainer that showed a fake connect-wallet dialog in dApps.
A clean 1.1.8 followed within the hour; over $600,000 was drained in the meantime.
Source: Sonatype post-mortem and Ledger’s incident report, 14 December 2023. History, not a warning about today — the verdict above is about maintenance now.
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/npm/@ledgerhq/connect-kit)
Watch it
Get told when @ledgerhq/connect-kit changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.