⚠️ Security Notice ⚠️
Please exercise caution and avoid interacting with broad dApps and wallets until they confirm they are unaffected.
✅ After an internal audit based on currently available information, our dApp is not affected. However, the full scope of the supply chain attack is still unclear. Since it acts like a replacer, please verify carefully before making any transaction or interaction (not just with SparkDEX).
We will continue monitoring the situation closely and update you as needed. Stay safe! 🔒
🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
The malicious payload works by silently swapping crypto addresses on the fly to steal funds.
If you use a hardware wallet, pay attention to every transaction before signing and you're safe.
If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.
It’s still unclear whether the attacker is also stealing seeds from software wallets directly at this stage.
Excellent report here:
jdstaerk.substack.com/p/we-j…