fc-updates
Important updates about things happening in Farcaster
21 replies
30 recasts
198 reactions
33 replies
66 recasts
311 reactions

Security Update: NPM QIX attack
1. If you're using the Farcaster app on web or mobile, you are safe.
2. If you're using a Farcaster miniapp, be cautious unless the developer has confirmed it's safe. Reject any transactions from miniapps you don’t fully understand.
What happened?
An attacker took over an NPM developer's account and replaced packages with malicious versions. These low-level, open-source components are used by many apps, including popular crypto wallets. Any app that updates these packages today may load the malicious code, which can propose dangerous transactions to users.
The Farcaster app uses some of these packages, but we have confirmed we haven’t updated them since the attack. It's therefore safe to use our app.
Farcaster miniapps could have been affected. If a miniapp is impacted, it may propose a dangerous transaction. Our security scanning should catch most of these, and even if something slips through, you’ll see a transaction preview to review and reject. If you’re using a miniapp, it’s important to read the details and accept only transactions you understand. 41 replies
164 recasts
565 reactions
4 replies
9 recasts
25 reactions
61 replies
77 recasts
461 reactions
0 reply
10 recasts
37 reactions
15 replies
11 recasts
104 reactions
40 replies
50 recasts
320 reactions
22 replies
10 recasts
146 reactions
49 replies
59 recasts
392 reactions
0 reply
0 recast
18 reactions
66 replies
118 recasts
572 reactions
50 replies
84 recasts
536 reactions
21 replies
43 recasts
289 reactions
31 replies
36 recasts
196 reactions