Slow fog: Attacker uses NPM to poison and injects malicious SVG, and induces DApp users to sign and steal coins through XSS pop-up windows
Source: PANews
Time: 2025-09-17 09:24:10
PANews reported on September 17 that 23pds, chief information security officer of Slow Mist Technology, posted on the X platform that recently, the attacker poisoned the NPM supply chain, replaced the SVG referenced by the decentralized platform with embedded malicious script files, and used SVG's XSS pop-up window to induce DApp users to sign and steal assets, pay attention to security.