Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
Hacken: There are scammers posing as project parties to induce developers and auditors to download suspicious repositories. Please be aware of the ri

Hacken: There are scammers posing as project parties to induce developers and auditors to download suspicious repositories. Please be aware of the ri

CointimeCointime2023/12/02 08:39
By:Cointime

Blockchain security organization Hacken has recently discovered a scam that has emerged on platforms such as Telegram and Linkedin. It is worth noting that this scam targets developers and auditors in the cryptocurrency industry.

Specifically, scammers on social networks specifically target individuals who provide technical services, convincing them to download a repository in the name of a legitimate project. In the repository, there is an unstable "npm run" command in the code. When executed, it may jeopardize the user's file system. This method is similar to previous scams involving fraudulent zip files and PDFs.

To strengthen defense against this strategy, consider the following measures:

- Be cautious when downloading repositories, especially when prompted by unfamiliar sources;

- Carefully check repository code using tools such as Semgrep or CodeQL and establish defined rules to ensure its safety when executed locally.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Ethereum Foundation Launches Trillion Dollar Security Initiative to Strengthen Network

The Ethereum Foundation has launched a “Trillion Dollar Security Initiative” to enhance the security and resilience of the Ethereum blockchain. This program aims to protect the network, which supports a wide range of decentralized finance applications, NFTs, and smart contracts.

DeFi Planet2025/05/15 19:55
Ethereum Foundation Launches Trillion Dollar Security Initiative to Strengthen Network

MetaMask Token Launch Remains Uncertain, Says Co-Founder Dan Finlay

MetaMask is still considering the launch of a native token, but no definitive plans have been made yet. Dan Finlay, MetaMask’s co-founder, described the possibility of a token as a “maybe” during an interview on The Block’s “Crypto Beat” podcast on May 14, 2025.

DeFi Planet2025/05/15 19:55
MetaMask Token Launch Remains Uncertain, Says Co-Founder Dan Finlay

Is the XRP price rally over for now?

Cointelegraph2025/05/15 19:11
Is the XRP price rally over for now?