Dec. 14, 2023, 8:02 p.m. | Ilkka Turunen

Security Boulevard securityboulevard.com


Earlier today, Ledger, a maker of hardware wallets for storing crypto, announced that they had identified malicious software embedded in one of their open source packages called @ledgerhq/connect-kit. This package is widely used as a connector between distributed blockchain applications and crypto wallets that back them up. This analysis delves into the specifics of the versions 1.1.5 to 1.1.7 compromise, cataloged in our data under sonatype-2023-4890.


The post Decrypting the Ledger connect-kit compromise: A deep dive into the crypto …

applications attack back blockchain called compromise connect connector crypto crypto wallets deep dive devzone distributed dive embedded hardware kit ledger malicious malicious software malware prevention open source open source packages package packages software sonatype lifecycle sonatype repository firewall today vulnerabilities wallets

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Offensive Security Engineer

@ Ivanti | United States, Remote

Senior Security Engineer I

@ Samsara | Remote - US

Senior Principal Information System Security Engineer

@ Chameleon Consulting Group | Herndon, VA

Junior Detections Engineer

@ Kandji | San Francisco

Data Security Engineer/ Architect - Remote United States

@ Stanley Black & Decker | Towson MD USA - 701 E Joppa Rd Bg 700