this post was submitted on 05 Dec 2024
14 points (100.0% liked)

Cybersecurity

5915 readers
282 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

Two spoofed versions of the Web3.js library were pushed out to capture private keys and send them to a hardcoded address.

top 2 comments
sorted by: hot top controversial new old
[–] [email protected] 5 points 1 month ago

And I just listened to Darknet Diaries latest episode on how someone had stolen tons of Solana

[–] [email protected] 3 points 1 month ago

“Earlier today, a publish-access account was compromised for @solana/web3.js, a JavaScript library that is commonly used by Solana dapps,” Anza said in a tweet on Wednesday. “This allowed an attacker to publish unauthorized and malicious packages that were modified, allowing them to steal private key material and drain funds from dapps, like bots, that handle private keys directly.”

yeesh.