4 ms·
looks like it won't affect you if you just downloaded the packages locally. the actual code only runs in a browser context - it replaces all crypto addresses i
by bstsb 1y ago
looks like it won't affect you if you just downloaded the packages locally.
the actual code only runs in a browser context - it replaces all crypto addresses in many places with the attacker's.
a list of the attacker's wallet addresses:
https://gist.github.com/sindresorhus/2b7466b1ec36376b8742dc711c24db20#file-npm-vulnerability-deobfusicated-js-L103 https://gist.github.com/sindresorhus/2b7466b1ec36376b8742dc7...
- pingou 1y agoI wonder why they didn't add something more nefarious that can run on developers machines while they were at it, would it have been too easy to see? It was caught very quickly anyway.
- keepamovin 1y agothat will still affect users of your website that uses these packages, tho.
- smoovb 1y agoEtherscan has tagged these addresses already. As of this check, none of the other block explorers have. Etherscan - yes - https://etherscan.io/address/0x4Cb4c0E7057829c378Eb7A9b174B004873b9D769 https://etherscan.io/address/0x4Cb4c0E7057829c378Eb7A9b174B0... Mempool.space - no Blockchair - no Tronscan - no Blockcypher.com - no Blockread.io - no