The non-profit cybersecurity organization Security Alliance (SEAL) states that recently, hackers have been exploiting security vulnerabilities in the open-source front-end JavaScript library React to implant crypto drainer programs that clear crypto wallets, with a noticeable increase in related attack activities. The React team disclosed on December 3rd that a white-hat hacker, Lachlan Davidson, discovered a security flaw in their software that allows attackers to remotely execute code without authentication, thereby inserting and running malicious code. SEAL also warned that this attack is not only targeting Web3 projects but could potentially affect all websites, and advised users to remain highly vigilant when signing any permit authorization signatures. (Cointelegraph)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
SEAL warns that React vulnerability has been exploited to implant a crypto wallet clearing program, with an increase in attack activity
The non-profit cybersecurity organization Security Alliance (SEAL) states that recently, hackers have been exploiting security vulnerabilities in the open-source front-end JavaScript library React to implant crypto drainer programs that clear crypto wallets, with a noticeable increase in related attack activities. The React team disclosed on December 3rd that a white-hat hacker, Lachlan Davidson, discovered a security flaw in their software that allows attackers to remotely execute code without authentication, thereby inserting and running malicious code. SEAL also warned that this attack is not only targeting Web3 projects but could potentially affect all websites, and advised users to remain highly vigilant when signing any permit authorization signatures. (Cointelegraph)