Many of us might have been seeing this circulating on X.
In simple term this is an attack or say hack into one of the most trusted NPM developers account, this Node Package Manager is the biggest host for JavaScript Packages. So it was found out that through phishing this hackers injected a malicious code into the packages which are capable of compromising many applications including wallet extensions most especially those hot wallets, in fact there is reports that it has been downloaded over billion times already. It can simply affect all chains and isn’t selective.
This does actually steals data but as an interceptor it can interact with affect apps and even changing things automatically.
What is your business with this;
Becareful with the kind of transactions you make and as usual check through transactions details before finally submitting it because this is the regular copy and paste address attack but it has the ability to change an address to another address if the application used is compromised.
This again calls for the use of cold wallet because it is reported that the attack is capable of getting info from wallet APIs which could lead to seedphrase exposure for online wallets.
This attacks also shows that no matter your knowledge you should extra careful still be a highly skilled developer like this was gotten through phishing attack from emails, so we all should be careful.
This tells us to start embracing cold storage more