Express

SlowMist: Attackers Poison NPM to Inject Malicious SVG, Leading DApp Users to Sign and Steal Coins via XSS Pop-ups

Summary: In a recent post on X platform, SlowMist Chief Information Security Officer 23pds warned that attackers have poisoned the NPM supply chain, replacing SVG files referenced by decentralized platforms with embedded malicious scripts to induce DApp users to sign and steal assets via XSS pop-ups. Stay vigilant.

In a recent post on X platform, SlowMist Chief Information Security Officer 23pds warned that attackers have poisoned the NPM supply chain, replacing SVG files referenced by decentralized platforms with embedded malicious scripts to induce DApp users to sign and steal assets via XSS pop-ups. Stay vigilant.

Last Update:

Tags:
Link: SlowMist: Attackers Poison NPM to Inject Malicious SVG, Leading DApp Users to Sign and Steal Coins via XSS Pop-ups   [Copy]
  • U.S. SEC Clears Path for Institutional Crypto Custody, Recognizing State Trust Companie... 6 hours ago
  • BTC Weekly Watch: Is the Rebound "Feast" Nearing Its End? 15 days ago
  • ​The Crypto Treasury Boom Meets Regulatory Chill: Is the DAT Frenzy Fading? 22 days ago
  • Nasdaq Takes Aim at 'Crypto-Flipping' Companies with Stricter Rules 26 days ago
  • BTC Weekly Outlook: The Oversold Bounce—A Bottom or a Shorting Opportunity? 28 days ago
  • You need to login to comment.