BTC $78,434.97 -1.19%
ETH $2,478.48 -0.39%
BNB $754.90 +1.50%
XRP $1.39 -0.80%
SOL $102.78 -1.54%
TRX $0.3378 +0.44%
DOGE $0.0891 -0.19%
ADA $0.2166 -0.01%
BCH $257.38 +1.32%
LINK $12.68 -3.71%
HYPE $83.96 -2.73%
AAVE $130.96 -1.12%
SUI $0.8183 +2.83%
XLM $0.1895 +0.72%
ZEC $1,121.69 -5.30%
BTC $78,434.97 -1.19%
ETH $2,478.48 -0.39%
BNB $754.90 +1.50%
XRP $1.39 -0.80%
SOL $102.78 -1.54%
TRX $0.3378 +0.44%
DOGE $0.0891 -0.19%
ADA $0.2166 -0.01%
BCH $257.38 +1.32%
LINK $12.68 -3.71%
HYPE $83.96 -2.73%
AAVE $130.96 -1.12%
SUI $0.8183 +2.83%
XLM $0.1895 +0.72%
ZEC $1,121.69 -5.30%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.