Scan to download
BTC $78,544.59 +3.53%
ETH $2,395.32 +3.21%
BNB $639.57 +1.48%
XRP $1.44 +0.78%
SOL $87.29 +1.85%
TRX $0.3300 -1.07%
DOGE $0.0961 +1.72%
ADA $0.2501 +0.37%
BCH $462.09 +3.42%
LINK $9.36 +0.36%
HYPE $41.35 +4.19%
AAVE $94.33 +3.29%
SUI $0.9525 +1.11%
XLM $0.1771 -0.40%
ZEC $318.88 +1.89%
BTC $78,544.59 +3.53%
ETH $2,395.32 +3.21%
BNB $639.57 +1.48%
XRP $1.44 +0.78%
SOL $87.29 +1.85%
TRX $0.3300 -1.07%
DOGE $0.0961 +1.72%
ADA $0.2501 +0.37%
BCH $462.09 +3.42%
LINK $9.36 +0.36%
HYPE $41.35 +4.19%
AAVE $94.33 +3.29%
SUI $0.9525 +1.11%
XLM $0.1771 -0.40%
ZEC $318.88 +1.89%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26
Collection

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.