Scan to download
BTC $78,845.92 -2.08%
ETH $2,220.19 -1.51%
BNB $664.29 -2.56%
XRP $1.42 -3.05%
SOL $88.33 -2.81%
TRX $0.3509 -0.61%
DOGE $0.1111 -2.85%
ADA $0.2574 -3.52%
BCH $423.18 -2.56%
LINK $9.92 -3.52%
HYPE $42.03 -8.21%
AAVE $90.16 -6.78%
SUI $1.07 -7.23%
XLM $0.1528 -4.07%
ZEC $500.82 -7.73%
BTC $78,845.92 -2.08%
ETH $2,220.19 -1.51%
BNB $664.29 -2.56%
XRP $1.42 -3.05%
SOL $88.33 -2.81%
TRX $0.3509 -0.61%
DOGE $0.1111 -2.85%
ADA $0.2574 -3.52%
BCH $423.18 -2.56%
LINK $9.92 -3.52%
HYPE $42.03 -8.21%
AAVE $90.16 -6.78%
SUI $1.07 -7.23%
XLM $0.1528 -4.07%
ZEC $500.82 -7.73%

Cosine: Beware of @solana/web3.js supply chain poisoning, the poisoned version has been taken down

2024-12-04 09:08:12
Collection

ChainCatcher message, Slow Mist Yu X stated: "Attention @solana/web3.js supply chain poisoning, known versions 1.95.6 and 1.95.7 contain backdoor code that can steal user private keys. The new version no longer has this risk. Well-known wallets have not found this risk, but real attacks have occurred.

It is speculated that perhaps third-party private key-related tools (including bots) that update dependency packages in a timely manner were affected, as the poisoned versions only lasted a few hours before being discovered and removed. If you are using this package, please be cautious and check."

app_icon
ChainCatcher Building the Web3 world with innovations.