The Solana Web3.js library, which is commonly used to create decentralized applications (dapps), was targeted in a supply chain attack. Bad versions of the library, specifically versions 1.95.6 and 1.95.7, were uploaded to the official GitHub account after an attacker gained access to it. These harmful versions included hidden code that could take users’ private keys and steal funds from affected dapps. The risky versions were available for about five hours on December 2, 2024, before they were taken down. A new, secure version (1.95.8) has been released, and developers who used the compromised versions are strongly advised to update right away and change all their keys and credentials.
Discover comprehensive supply chain report news insights at The Supply Chain Report. For international trade resources, visit ADAMftd.com.
#SolanaWeb3js #DecentralizedApplications #SupplyChainAttack #CryptoSecurity #GitHubCompromise #Web3Security #PrivateKeyTheft #DappSecurity #SolanaUpdate #SecureDevelopment #CryptoDevelopers #SolanaLibrary #SecurityPatch #SoftwareSecurity