What happened with @Ledger connect-kit in few points:. Someone deployed malicious version of @.

14 Dec 2023, 14:06
What happened with @Ledger connect-kit in few points: 1. Someone deployed malicious version of @.ledgerhq/connect-kit which was loaded by @.ledgerhq/connect-kit-loader in dynamic and very unsafe way, just loading any version that would be v1.x.x which allowed that attack

Same news in other sources

1
THORSwap
THORSwapTHOR #3496
Twitter
14 Dec 2023, 14:15
🚨 Alert 🚨 There is a serious security issue present with the popular library connect-kit maintained by Ledger that drains wallets instead of doing user-intended transactions. THORSwap web app, THORSwap Ledger Live and THORSwap SwapKit libraries are all unaffected and do not…
Alert.
🚨 Alert 🚨 There is a serious security issue present with the popular library connect-kit maintained by Ledger that drains wallets instead of doing user-intended transactions. THORSwap web app, THORSwap Ledger Live and THORSwap SwapKit libraries are all unaffected and do not…