Dec. 14, 2023, 8:05 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


Earlier today, Ledger, a maker of hardware wallets for storing crypto, announced that they had identified malicious software embedded in one of their open source packages called @ledgerhq/connect-kit. This package is widely used as a connector between distributed blockchain applications and crypto wallets that back them up. This analysis delves into the specifics of the versions 1.1.5 to 1.1.7 compromise, cataloged in our data under sonatype-2023-4890.


Article Link: Decrypting the Ledger connect-kit compromise: A deep dive into the crypto …

applications attack back blockchain called compromise connect connector crypto crypto wallets deep dive distributed dive embedded hardware kit ledger malicious malicious software open source open source packages package packages software today wallets

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)