Scan to download
BTC $60,871.92 +0.10%
ETH $1,560.18 -3.15%
BNB $575.96 -1.68%
XRP $1.10 -0.16%
SOL $62.77 -3.52%
TRX $0.3207 -1.05%
DOGE $0.0821 -0.68%
ADA $0.1603 -0.39%
BCH $219.03 -0.31%
LINK $7.40 -0.60%
HYPE $58.81 -4.32%
AAVE $61.42 -3.00%
SUI $0.7197 +2.38%
XLM $0.2043 +7.53%
ZEC $363.78 +15.48%
BTC $60,871.92 +0.10%
ETH $1,560.18 -3.15%
BNB $575.96 -1.68%
XRP $1.10 -0.16%
SOL $62.77 -3.52%
TRX $0.3207 -1.05%
DOGE $0.0821 -0.68%
ADA $0.1603 -0.39%
BCH $219.03 -0.31%
LINK $7.40 -0.60%
HYPE $58.81 -4.32%
AAVE $61.42 -3.00%
SUI $0.7197 +2.38%
XLM $0.2043 +7.53%
ZEC $363.78 +15.48%

Cosine: Beware of @solana/web3.js supply chain poisoning, the poisoned version has been taken down

2024-12-04 09:08:12
Collection

ChainCatcher message, Slow Mist Yu X stated: "Attention @solana/web3.js supply chain poisoning, known versions 1.95.6 and 1.95.7 contain backdoor code that can steal user private keys. The new version no longer has this risk. Well-known wallets have not found this risk, but real attacks have occurred.

It is speculated that perhaps third-party private key-related tools (including bots) that update dependency packages in a timely manner were affected, as the poisoned versions only lasted a few hours before being discovered and removed. If you are using this package, please be cautious and check."

app_icon
ChainCatcher Building the Web3 world with innovations.