Slow Fog: Attackers use NPM poisoning to inject malicious SVG, inducing DApp users to sign and steal coins through XSS pop-ups.

PANews, September 17 - 23pds, the Chief Information Security Officer of Slow Fog Technology, stated in a post on the X platform that recently attackers poisoned the NPM Supply Chain, replacing the SVG referenced by Decentralization platforms with embedded malicious script files, using SVG's XSS pop-ups to induce DApp users to sign and steal assets. Please pay attention to security.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)