Security Agency: NPM Supply Chain Attacked, Developer qix Affected

PANews September 9th news, according to Scam Sniffer, renowned developer qix had their npm packages injected with malicious code due to a phishing attack, with related packages including chalk, strip-ansi, color-convert, and others. The attack method involved hooking wallet functions, tampering with ETH/SOL transaction receiving addresses, and replacing addresses in network responses. User advice: Be sure to verify the recipient and amount on the wallet interface, check for changes in the pasted address, review recent transactions, and prioritize using a hardware wallet for high-value operations.

ETH1.09%
SOL1.71%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 1
  • Repost
  • Share
Comment
0/400
GateUser-579afc35vip
· 12h ago
Hold on tight, we are about to To da moon 🛫
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)