Scan to download
BTC $66,783.99 +0.14%
ETH $2,037.93 +1.65%
BNB $612.26 +0.33%
XRP $1.33 +0.56%
SOL $83.22 +1.76%
TRX $0.3197 -1.12%
DOGE $0.0913 +0.03%
ADA $0.2450 +1.49%
BCH $461.44 +1.59%
LINK $8.69 +2.47%
HYPE $37.11 -3.74%
AAVE $97.49 +1.74%
SUI $0.8681 +2.56%
XLM $0.1694 +2.56%
ZEC $230.14 +4.72%
BTC $66,783.99 +0.14%
ETH $2,037.93 +1.65%
BNB $612.26 +0.33%
XRP $1.33 +0.56%
SOL $83.22 +1.76%
TRX $0.3197 -1.12%
DOGE $0.0913 +0.03%
ADA $0.2450 +1.49%
BCH $461.44 +1.59%
LINK $8.69 +2.47%
HYPE $37.11 -3.74%
AAVE $97.49 +1.74%
SUI $0.8681 +2.56%
XLM $0.1694 +2.56%
ZEC $230.14 +4.72%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26
Collection

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.