Scan to download
BTC $79,080.99 -2.08%
ETH $2,226.90 -1.50%
BNB $669.90 -1.27%
XRP $1.44 -2.85%
SOL $89.06 -2.71%
TRX $0.3513 -0.40%
DOGE $0.1124 -2.57%
ADA $0.2611 -2.89%
BCH $425.55 -2.20%
LINK $10.06 -3.19%
HYPE $43.15 -5.56%
AAVE $92.67 -5.08%
SUI $1.09 -6.92%
XLM $0.1549 -3.86%
ZEC $510.08 -6.25%
BTC $79,080.99 -2.08%
ETH $2,226.90 -1.50%
BNB $669.90 -1.27%
XRP $1.44 -2.85%
SOL $89.06 -2.71%
TRX $0.3513 -0.40%
DOGE $0.1124 -2.57%
ADA $0.2611 -2.89%
BCH $425.55 -2.20%
LINK $10.06 -3.19%
HYPE $43.15 -5.56%
AAVE $92.67 -5.08%
SUI $1.09 -6.92%
XLM $0.1549 -3.86%
ZEC $510.08 -6.25%

Cosine: Beware of @solana/web3.js supply chain poisoning, the poisoned version has been taken down

2024-12-04 09:08:12
Collection

ChainCatcher message, Slow Mist Yu X stated: "Attention @solana/web3.js supply chain poisoning, known versions 1.95.6 and 1.95.7 contain backdoor code that can steal user private keys. The new version no longer has this risk. Well-known wallets have not found this risk, but real attacks have occurred.

It is speculated that perhaps third-party private key-related tools (including bots) that update dependency packages in a timely manner were affected, as the poisoned versions only lasted a few hours before being discovered and removed. If you are using this package, please be cautious and check."

app_icon
ChainCatcher Building the Web3 world with innovations.