We found results for “”
MSC-2023-18370
Date: December 15, 2023
@ledgerhq/connect-kit allows web3 apps to connect to Ledger hardware wallets. Versions 1.1.5, 1.1.6, 1.1.7 were compromised by a threat actor to include malicious code that automatically steals crypto and NFT's from wallets that connect to the app. Those versions were deleted and we recommend updating to 1.1.8 version. Ledger has advised users to 'Clear Sign' all transactions, following these instructions: https://www.ledger.com/blog/clear-sign-your-worries-away.
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Embedded Malicious Code
CWE-506CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | HIGH |