Sort:  

🚨 A major supply chain attack is currently underway: a well-known developer's NPM account has been breached. The compromised packages have been downloaded more than 1 billion times, putting the entire JavaScript ecosystem in potential danger.

The malicious code replaces crypto addresses stealthily to steal funds.

If you're using a hardware wallet, scrutinize every transaction before signing for security.

Those without a hardware wallet should avoid on-chain transactions for now.

It's uncertain whether the attacker is also extracting seeds from software wallets at this time.