BTC $64,626.84 +0.53%
ETH $1,914.12 +0.54%
BNB $602.97 -0.20%
XRP $1.00 +0.05%
SOL $76.98 +1.64%
TRX $0.3326 +0.44%
DOGE $0.0700 -0.15%
ADA $0.1728 -0.45%
BCH $203.62 -0.22%
LINK $9.49 -0.07%
HYPE $58.42 -1.31%
AAVE $87.15 -1.61%
SUI $0.6499 -3.29%
XLM $0.1545 -1.84%
ZEC $508.83 -0.72%
BTC $64,626.84 +0.53%
ETH $1,914.12 +0.54%
BNB $602.97 -0.20%
XRP $1.00 +0.05%
SOL $76.98 +1.64%
TRX $0.3326 +0.44%
DOGE $0.0700 -0.15%
ADA $0.1728 -0.45%
BCH $203.62 -0.22%
LINK $9.49 -0.07%
HYPE $58.42 -1.31%
AAVE $87.15 -1.61%
SUI $0.6499 -3.29%
XLM $0.1545 -1.84%
ZEC $508.83 -0.72%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.