Scan to download
BTC $75,590.88 +1.40%
ETH $2,356.60 +0.93%
BNB $632.64 +1.97%
XRP $1.45 +2.77%
SOL $88.18 +3.74%
TRX $0.3237 -1.03%
DOGE $0.0987 +2.62%
ADA $0.2576 +3.71%
BCH $449.59 +2.20%
LINK $9.52 +2.79%
HYPE $43.56 -2.47%
AAVE $117.16 +10.35%
SUI $0.9997 +3.22%
XLM $0.1693 +5.54%
ZEC $332.39 -3.29%
BTC $75,590.88 +1.40%
ETH $2,356.60 +0.93%
BNB $632.64 +1.97%
XRP $1.45 +2.77%
SOL $88.18 +3.74%
TRX $0.3237 -1.03%
DOGE $0.0987 +2.62%
ADA $0.2576 +3.71%
BCH $449.59 +2.20%
LINK $9.52 +2.79%
HYPE $43.56 -2.47%
AAVE $117.16 +10.35%
SUI $0.9997 +3.22%
XLM $0.1693 +5.54%
ZEC $332.39 -3.29%

Cosine: Beware of @solana/web3.js supply chain poisoning, the poisoned version has been taken down

2024-12-04 09:08:12
Collection

ChainCatcher message, Slow Mist Yu X stated: "Attention @solana/web3.js supply chain poisoning, known versions 1.95.6 and 1.95.7 contain backdoor code that can steal user private keys. The new version no longer has this risk. Well-known wallets have not found this risk, but real attacks have occurred.

It is speculated that perhaps third-party private key-related tools (including bots) that update dependency packages in a timely manner were affected, as the poisoned versions only lasted a few hours before being discovered and removed. If you are using this package, please be cautious and check."

app_icon
ChainCatcher Building the Web3 world with innovations.