Scan to download
BTC $61,073.20 -1.42%
ETH $1,571.35 -4.86%
BNB $575.46 -2.42%
XRP $1.09 -2.02%
SOL $62.91 -4.19%
TRX $0.3201 -1.47%
DOGE $0.0820 -1.54%
ADA $0.1580 -2.15%
BCH $217.29 -1.17%
LINK $7.38 -1.80%
HYPE $59.33 -4.73%
AAVE $62.00 -4.71%
SUI $0.7114 +0.65%
XLM $0.2012 +6.97%
ZEC $370.70 +16.79%
BTC $61,073.20 -1.42%
ETH $1,571.35 -4.86%
BNB $575.46 -2.42%
XRP $1.09 -2.02%
SOL $62.91 -4.19%
TRX $0.3201 -1.47%
DOGE $0.0820 -1.54%
ADA $0.1580 -2.15%
BCH $217.29 -1.17%
LINK $7.38 -1.80%
HYPE $59.33 -4.73%
AAVE $62.00 -4.71%
SUI $0.7114 +0.65%
XLM $0.2012 +6.97%
ZEC $370.70 +16.79%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26
Collection

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.