This isn't just a web3 problem. The same attack works on any developer who clones a repo and runs it. If someone sends you a project to review, read it first. @levelsio@thepatwalls@starter_story@marclou
The attack vector here is the same one used in the @DriftProtocol hack last week. A contributor was compromised after cloning a code repository shared by the group. $285 million gone.