๐จ Thereโs a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.
The malicious payload works by silently swapping crypto addresses on the fly to steal funds.
If you use a hardware wallet, pay attention to every transaction before signing and you're safe.
If you donโt use a hardware wallet, refrain from making any on-chain transactions for now.
Itโs still unclear whether the attacker is also stealing seeds from software wallets directly at this stage.
Excellent report here: https://t.co/5CtiZJHYsN
I would strongly recommend not signing any crypto transactions right now.
There is a huge supply chain attack on popular NPM packages that may have compromised various crypto websites (frontend, not the actual contracts).
It changes the destination address of transactions and approvals to be the attacker's addresses rather than the address you're actually trying to interact with.
@3nergywhiz@Claynosaurz https://t.co/HWPUJdiLed
Though these were from the limited edition Solana shop
Best to check @Claynosaurz own handle and links for safety though!
1/ Weโve been deep in build mode for months, and weโre excited to show you what we've been working on.
Introducing the next chapter of Solana Mobile: the Solana Seeker ๐งต๐
The @CyberFrogsNFT upgrade reminds me of the @y00tsNFT reveal back in the days. Awesome traits and colours.
Just pick one for yourself that matches them well.
No more floor frogs.
Best art on solana