Skip to content

Commit de6d2d1

Browse files
authored
Update software-supply-chain-attacks-crypto.md
1 parent 681616b commit de6d2d1

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

software-supply-chain-attacks-crypto.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -134,7 +134,9 @@ Ref:
134134
* <https://www.mend.io/blog/the-solana-web3-js-incident-another-wake-up-call-for-supply-chain-security/>
135135
* <https://x.com/blockaid_/status/1864069590147277261>
136136

137-
137+
More fake and malicious solana packages:
138+
* solanacore, see <https://platform.safedep.io/community/malysis/01JGVKW3NNZFJMSX4F9JN40CNN>
139+
* walletcore-gen, see <https://twitter.com/npm_malware/status/1876328153880342680>
138140
## Hardware attacks
139141

140142
It is possible to tamper with hardware devices used in crypto, typically a hardware wallet. Who would do that: an employee at the company that designed the wallet, the factory that produced it, and everyone involved in shipping it. Ref: <https://vitalik.ca/general/2021/01/11/recovery.html>. Such a real hardware supply chain attack has happened on Trezor wallets (2022): <https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/>

0 commit comments

Comments
 (0)