source avatarMuhammad Azhar

Share

BSV's wallet-toolbox shipped 2.4.0 to npm on 6 July with a changelog line naming GHSA-36f9-7rg5-cpf8 and describing the attack. The advisory itself wasn't published until 24 September. With remote storage, the default setup, older versions signed whatever recipient script the storage server sent back while the app kept showing the address you'd typed. 556 of last week's 1,866 downloads were still a version inside the affected range. Dependabot alerts key off the advisory database, so for those 11 weeks the warning sat in a changelog. Does anyone actually read dependency changelogs for GHSA ids, or is everyone waiting on the alert?

No.0 picture
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.