Scan to download
BTC $66,340.17 -1.62%
ETH $1,952.74 -1.94%
BNB $603.79 -2.22%
XRP $1.42 -3.87%
SOL $81.38 -4.42%
TRX $0.2784 -1.19%
DOGE $0.0983 -2.54%
ADA $0.2726 -2.98%
BCH $557.42 -0.98%
LINK $8.59 -2.71%
HYPE $28.40 -3.19%
AAVE $122.89 -2.88%
SUI $0.9281 -4.12%
XLM $0.1605 -3.16%
ZEC $263.56 -10.70%
BTC $66,340.17 -1.62%
ETH $1,952.74 -1.94%
BNB $603.79 -2.22%
XRP $1.42 -3.87%
SOL $81.38 -4.42%
TRX $0.2784 -1.19%
DOGE $0.0983 -2.54%
ADA $0.2726 -2.98%
BCH $557.42 -0.98%
LINK $8.59 -2.71%
HYPE $28.40 -3.19%
AAVE $122.89 -2.88%
SUI $0.9281 -4.12%
XLM $0.1605 -3.16%
ZEC $263.56 -10.70%

Slow Fog: Dapps using Ledger Connect Kit version 1.1.4 and above are affected, please pay attention to the investigation

2023-12-14 21:52:26
Collection

ChainCatcher message, SlowMist Security Threat Intelligence discovered that @ledgerhq/connect-kit has suffered a supply chain attack, where the attacker implanted malicious JS code in versions of @ledgerhq/connect-kit >1.1.4 to launch phishing attacks against cryptocurrency users. Dapps using @ledgerhq/connect-kit version >1.1.4 are all affected, please check if the following affected versions are used in your code.

Affected version range:

@ledgerhq/connect-kit 1.1.5 (the attacker left a message in the code)

@ledgerhq/connect-kit 1.1.6 (the attacker left a message in the code and implanted malicious JS code)

@ledgerhq/connect-kit 1.1.7 (the attacker left a message in the code and implanted malicious JS code)

The SlowMist Security Team recommends exercising caution when interacting with DApps until an official fix is clearly provided.

app_icon
ChainCatcher Building the Web3 world with innovations.