Cybersecurity non-profit organization Security Alliance (SEAL) states that recently, hackers have been exploiting security vulnerabilities in the open-source front-end JavaScript library React to embed crypto drainers that clear cryptocurrency wallets, with a noticeable increase in related attack activities. The React team disclosed on December 3rd that a white-hat hacker, Lachlan Davidson, discovered a security flaw in their software that allows attackers to remotely execute code without authentication, enabling the insertion and execution of malicious code. SEAL also warns that this attack is not only targeting Web3 projects but could potentially affect all websites, and advises users to remain highly vigilant when signing any permit authorization signatures. (Cointelegraph)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Cybersecurity non-profit organization Security Alliance (SEAL) states that recently, hackers have been exploiting security vulnerabilities in the open-source front-end JavaScript library React to embed crypto drainers that clear cryptocurrency wallets, with a noticeable increase in related attack activities. The React team disclosed on December 3rd that a white-hat hacker, Lachlan Davidson, discovered a security flaw in their software that allows attackers to remotely execute code without authentication, enabling the insertion and execution of malicious code. SEAL also warns that this attack is not only targeting Web3 projects but could potentially affect all websites, and advises users to remain highly vigilant when signing any permit authorization signatures. (Cointelegraph)