We found results for “”
MSC-2023-18368
Date: December 15, 2023
@ledgerhq/connect-kit allows web3 apps to connect to Ledger hardware wallets. Versions 1.1.5, 1.1.6, 1.1.7 were compromised by a threat actor to include malicious code that automatically steals crypto and NFT's from wallets that connect to the app. Those versions were deleted and we recommend updating to 1.1.8 version. Ledger has advised users to 'Clear Sign' all transactions, following these instructions: https://www.ledger.com/blog/clear-sign-your-worries-away.
Language: JS
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Embedded Malicious Code
CWE-506CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | HIGH |