BTC $78,343.23 -1.33%
ETH $2,472.40 -0.71%
BNB $753.42 +1.23%
XRP $1.39 -0.45%
SOL $102.87 -1.93%
TRX $0.3378 +0.39%
DOGE $0.0895 -0.12%
ADA $0.2176 -0.92%
BCH $255.55 -0.28%
LINK $12.53 -5.38%
HYPE $83.55 -4.95%
AAVE $129.99 -3.07%
SUI $0.8148 +0.24%
XLM $0.1893 -1.23%
ZEC $1,150.22 -4.08%
BTC $78,343.23 -1.33%
ETH $2,472.40 -0.71%
BNB $753.42 +1.23%
XRP $1.39 -0.45%
SOL $102.87 -1.93%
TRX $0.3378 +0.39%
DOGE $0.0895 -0.12%
ADA $0.2176 -0.92%
BCH $255.55 -0.28%
LINK $12.53 -5.38%
HYPE $83.55 -4.95%
AAVE $129.99 -3.07%
SUI $0.8148 +0.24%
XLM $0.1893 -1.23%
ZEC $1,150.22 -4.08%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.