Telegram (AI) YouTube Facebook X
Ру
Ethereum developers targeted via fake Hardhat plugins

Ethereum developers targeted via fake Hardhat plugins

Cybercriminals uploaded at least 20 malicious packages to npm, posing as Hardhat by the Nomic Foundation—a popular development environment for smart contracts and dapps on the Ethereum blockchain, according to Socket analysts.

Using typosquatting, the malware attempted to pass itself off as legitimate packages. The ultimate goal was to steal private keys and other sensitive data.

The malicious packages were downloaded more than 1,000 times in total.

According to experts, the attackers could have gained unauthorised access to production systems and API keys for third-party services, compromised smart contracts, or deployed malicious versions of existing dapps for subsequent attacks.

In December 2024, hackers targeted Solana developers via a library swap in JavaScript.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK