🚨 A massive supply chain attack is underway: a reputable developer's NPM account has been compromised. The affected packages have been downloaded over 1 billion times, potentially putting the entire JavaScript ecosystem at risk.
The malicious payload works by silently and dynamically swapping crypto addresses to steal funds.
If you use a hardware wallet, carefully check each transaction before signing, and you'll be safe.
If you don't use a hardware wallet, refrain from making any on-chain transactions for now.
It's unclear whether the attackers also stole seeds directly from software wallets.
For the excellent report, click here: https://t.co/5CtiZJHYsN