🚨SlowMist TI Alert🚨
Massive NPM supply chain attack unfolding…
📩A reputable developer’s NPM account was phished via fake “NPM 2FA update” emails, enabling attackers to inject an obfuscated index.js into popular packages (>1B downloads).
The payload hijacks browser wallets (e.g. 🦊MetaMask) and intercepts network requests (fetch & XMLHttpRequest), silently swapping crypto addresses ( #ETH / #BTC / #SOL / #TRX) to attacker wallet 0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976.
đź”’ Immediate actions:
👨‍💻 Devs/Wallets/DeFi → audit deps, rotate creds, remove compromised pkgs.
🔑 Users → prefer HW wallets & verify every tx.
⛔ SW wallet users → avoid on-chain txs until safe.
Stay vigilant! ⚠️
#Security #SupplyChainAttack
Show original18.6K
28
The content on this page is provided by third parties. Unless otherwise stated, OKX is not the author of the cited article(s) and does not claim any copyright in the materials. The content is provided for informational purposes only and does not represent the views of OKX. It is not intended to be an endorsement of any kind and should not be considered investment advice or a solicitation to buy or sell digital assets. To the extent generative AI is utilized to provide summaries or other information, such AI generated content may be inaccurate or inconsistent. Please read the linked article for more details and information. OKX is not responsible for content hosted on third party sites. Digital asset holdings, including stablecoins and NFTs, involve a high degree of risk and can fluctuate greatly. You should carefully consider whether trading or holding digital assets is suitable for you in light of your financial condition.