There has been a massive security breach, please read this whole post.
Anyone who has:
1. Watched my Hardhat Javascript course from 2022 within the last 14 days, and didn't use my lock file
2. Done any development work with blockchain wallets/UI
3. Interacted with Solana Hello World applications
Within the last 2 weeks, you may have a critical security breach in your system designed to steal your keys.
How to check if you are affected:
1. Check your `yarn.lock`/`package-lock.json` files asap to make sure you are not using `1.95.6` or `1.95.7` of the @solana/web3.js app.
A grep command like so:
```
grep -r "@solana/web3.js" .
```
Can help you for your local directories.
2. You can run a search on GitHub with:
```
user:YOUR_USERNAME "@solana/web3.js"
```
to see if you used it on GitHub.
The bug affects the following versions:
- 1.95.6
- 1.95.7
These have been removed from the npm website, and the new version is reportedly clean.
What to do if you find such a version:
1. Delete the package
2. Consider your private keys compromised, and start to move your funds to new keys
As of writing, I'm not sure if updating the package fixes the bug. We will have to stay tuned to security researchers.