Global Feed Post Login
Replying to Avatar FLASH

⚡️🚨 ALERT - Aikido Security has flagged what may be the largest npm supply chain hack ever targeting crypto holders.

A long-trusted maintainer (“qix”) was phished, and 18 popular packages, including chalk, debug, and ansi-styles (2B+ weekly downloads), were injected with wallet-draining code.

The malware silently swaps crypto addresses in MetaMask, Phantom, and other software wallets. Users see the correct recipient, but funds are rerouted to attacker-controlled addresses.

The compromised packages have already been downloaded over 1B times, putting the entire JavaScript ecosystem at risk.

🔒 Hardware wallet users: verify every transaction before signing.

⚠️ Software wallet users: avoid on-chain transactions for now.

Avatar
Scott 3mo ago 💬 2

How does this affect address generation on a watch only wallet on mobile? nostr:nprofile1qqsvxq03xdev3uxehjqcdkr5lfzl5vawmcf7vm6ps73m6ghwg8y4k2spz4mhxue69uhk2er9dchxummnw3ezumrpdejqz9nhwden5te0dehhxarj9eekcmm5dpujuamfdcq9v6rc

nostr:nevent1qqswl65hdz9rswaawpkcq7un2n5n2mnvp8x4d5fvsv2euszllseas3cpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgq3qf4uyypghstsd8l4sxng4ptwzk6awfm3mf9ux0yallfrgkm6mj6esxpqqqqqqzavan4g

Reply to this note

Please Login to reply.

Discussion

Avatar
Maria2000 3mo ago

https://www.youtube.com/live/R0M2TL7RARw

Thread collapsed
Avatar
nunchuk_io 3mo ago

Nunchuk unaffected. We don’t use Javascript.

https://primal.net/e/nevent1qqs04ag02shk3fw998vlrmp763psj6tne2umq6vctzlwd52vc4wvg6gu3wy3s

Thread collapsed