SlowMist: gli aggressori usano NPM per avvelenare SVG dannoso e ingannare gli utenti DAPP nella firma per rubare le monete attraverso i popup XSS
Fonte: CoinWorld
Ora: 2025-09-17 09:28:59
According to Bijie.com, 23pds, chief information security officer of Slow Mist Technology, posted on the X platform that recently attackers poisoned the NPM supply chain, replaced the SVG referenced by the decentralized platform with embedded malicious script files, and used SVG's XSS pop-up window to induce DApp users to sign, steal user assets, and pay attention to security.