🚨Important update🚨
💀There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised
🧑💻The code stole crypto by hijacking browser wallet transactions
🤷In Simple terms - You try to send 1 ETH to your friend’s wallet The malicious code changes it behind the scenes to hacker wallet before it’s sent
👇How to protect yourself?
❌Don't do any txn today
✅Wait for more updates
✅If any urgent txn, read what you're wallet says before sign
✅Try to avoid Testnet grinding today
❌Even HW wallet can't protect u, if u sign wrong txn
🤔So far no confirmation if this attack stealing seed from software wallets
✅If u have HW wallet u r safe from this part, because seed is stored in HW
✅Say safe
📸Image from Ledger CTO's article below
💙Like
🔁RT
🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
The malicious payload works by silently swapping crypto addresses on the fly to steal funds.
If you use a hardware wallet, pay attention to every transaction before signing and you're safe.
If you don’t use a hardware wallet, refrain from making any on-chain transactions for now.
It’s still unclear whether the attacker is also stealing seeds from software wallets directly at this stage.
Excellent report here:
jdstaerk.substack.com/p/we-j…