最新报道:According to Bijie.com, regarding the "NPM supply chain attack," OKX Wallet stated that OKX always prioritizes system security and strictly controls the risks of using third-party components throughout the entire product development and launch process. An internal review and assessment confirmed that the OKX app, developed based on native Android and iOS frameworks, poses no security risks. OKX plugins, web applications, and mobile DApp browsers do not use the affected third-party components. All platform services are operating normally, and users can continue to use them with confidence. According to Bijie.com, attackers stole the NPM account credentials of developer qix via a phishing email disguised as npmjs support. They then injected malicious code into 18 popular JavaScript packages released by qix, including chalk and debug-js, which have over 2 billion weekly downloads. This attack is considered the largest supply chain attack in history. Notably, the malicious code did not attempt to locally install a trojan or steal files, but instead specifically targeted Web 3 scenarios: if it detected the presence of window.ethereum in the browser environment, it would hijack transaction requests. The malicious code tampered with the browser's Ethereum and Solana transaction requests, redirecting funds to addresses controlled by the attacker (such as the Ethereum address 0xFc4a4858... ) and stealing assets by replacing the encrypted addresses in the JSON response. Although the page displayed the legitimate transaction address, the funds were actually transferred to the attacker's address.