Enguerrand Allamel

@enguerrand.dev

Staff Cloud Security Engineer @Ledger

"Census III of Free and hashtag#OpenSource Software: Application Libraries leans on more than 12M data points from security tools such as Black Duck, FOSSA, Snyk, and Sonatype, which have been deployed at more than 10k companies" techcrunch.com/2024/12/04/l...

Linux Foundation report highlights the true state of open source libraries in production apps | TechCrunch

A new report from the Linux Foundation highlights the true state of open source libraries in production apps.

techcrunch.com

Exclusive: The backdoor inserted in v1.95.7 adds an "addToQueue" function which exfiltrates the private key through seemingly-legitimate CloudFlare headers. Calls to this function are then inserted in various places that (legitimately) access the private key.

BildBild
Socket@socket.dev · 2y ago

🚨 A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular #Solana web3.js library. The injected code captures private keys and transmits them to a hardcoded address. This is a developing story. socket.dev/blog/supply-... #crypto #cybersecurity