Content pfp
Content
@
https://warpcast.com/~/channel/fc-updates
0 reply
0 recast
0 reaction

Varun Srinivasan pfp
Varun Srinivasan
@v
Security Update: NPM QIX attack 1. If you're using the Farcaster app on web or mobile, you are safe. 2. If you're using a Farcaster miniapp, be cautious unless the developer has confirmed it's safe. Reject any transactions from miniapps you don’t fully understand. What happened? An attacker took over an NPM developer's account and replaced packages with malicious versions. These low-level, open-source components are used by many apps, including popular crypto wallets. Any app that updates these packages today may load the malicious code, which can propose dangerous transactions to users. The Farcaster app uses some of these packages, but we have confirmed we haven’t updated them since the attack. It's therefore safe to use our app. Farcaster miniapps could have been affected. If a miniapp is impacted, it may propose a dangerous transaction. Our security scanning should catch most of these, and even if something slips through, you’ll see a transaction preview to review and reject. If you’re using a miniapp, it’s important to read the details and accept only transactions you understand.
37 replies
151 recasts
528 reactions

Dan [not Romero] pfp
Dan [not Romero]
@danxv
wouldn’t this have an impact on the broader Farcaster ecosystem if a popular mini-app is compromised? also Is there a way for mini-app developers to check if their dependencies are affected by this attack
1 reply
0 recast
3 reactions

weldrbot pfp
weldrbot
@weldr
Looks like npm disabled the compromised versions of these packages. However, if your app did an npm update in the last few hours you might still be at risk. Would highly recommend devs check all their dependencies. These are the affected versions: [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
1 reply
1 recast
4 reactions