Scan to download
BTC $62,583.90 +2.81%
ETH $1,629.55 +4.26%
BNB $593.80 +3.29%
XRP $1.12 +4.64%
SOL $65.06 +3.94%
TRX $0.3286 +2.72%
DOGE $0.0845 +3.82%
ADA $0.1650 +5.50%
BCH $224.31 +2.30%
LINK $7.76 +5.87%
HYPE $58.96 -1.21%
AAVE $63.35 +3.19%
SUI $0.7520 +7.12%
XLM $0.2054 +3.56%
ZEC $413.81 +12.52%
BTC $62,583.90 +2.81%
ETH $1,629.55 +4.26%
BNB $593.80 +3.29%
XRP $1.12 +4.64%
SOL $65.06 +3.94%
TRX $0.3286 +2.72%
DOGE $0.0845 +3.82%
ADA $0.1650 +5.50%
BCH $224.31 +2.30%
LINK $7.76 +5.87%
HYPE $58.96 -1.21%
AAVE $63.35 +3.19%
SUI $0.7520 +7.12%
XLM $0.2054 +3.56%
ZEC $413.81 +12.52%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26
Collection

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.