BTC $64,085.61 -1.08%
ETH $1,859.39 -1.17%
BNB $561.04 -1.01%
XRP $1.08 -1.63%
SOL $73.90 -2.38%
TRX $0.3301 +1.02%
DOGE $0.0689 -0.56%
ADA $0.1632 -3.67%
BCH $209.20 -0.53%
LINK $8.34 -1.58%
HYPE $58.27 +0.33%
AAVE $93.90 -1.70%
SUI $0.7076 -4.92%
XLM $0.1769 -2.88%
ZEC $494.32 -3.04%
BTC $64,085.61 -1.08%
ETH $1,859.39 -1.17%
BNB $561.04 -1.01%
XRP $1.08 -1.63%
SOL $73.90 -2.38%
TRX $0.3301 +1.02%
DOGE $0.0689 -0.56%
ADA $0.1632 -3.67%
BCH $209.20 -0.53%
LINK $8.34 -1.58%
HYPE $58.27 +0.33%
AAVE $93.90 -1.70%
SUI $0.7076 -4.92%
XLM $0.1769 -2.88%
ZEC $494.32 -3.04%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26
Collection

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.