Activity
Mon
Wed
Fri
Sun
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
What is this?
Less
More

Memberships

Web3 Builders Hub

25 members • Free

1 contribution to Web3 Builders Hub
Massive NPM supply-chain hack targeting crypto users
Big warning: a huge NPM supply-chain hack is live. Some web apps pulled bad scripts. The code runs in your browser. It watches your crypto transfers and swaps the address to the attacker’s. This hits ETH, BTC, SOL, TRX, LTC, and BCH. It’s dangerous because it works at many layers - it can change what you see, mess with API calls, and trick apps about what you’re signing. If you use a hardware wallet, slow down. Read the device screen for chain, amount, and the full address. Only then press confirm. No hardware wallet? Best move is to pause on-chain transactions for now - that’s what Ledger’s CTO advises. Be extra careful. Use only apps you really trust. Turn off browser extensions. Clear cache. Run a malware scan. Revoke risky approvals. Use transaction simulation. Stay safe and share with your friends.
1 like • Sep 15
Also of note is the attack used a string distance algorithm so that the malicious address would look similar to the real one, so quick glance might not be enough
1-1 of 1
Karolis Poviliūnas
1
4points to level up
@karolis-mikalauskas-5599
Hodl

Active 28d ago
Joined Sep 1, 2025
ENTP
Vilnius, Lithuania