CoinFeed
SlowMist: Attackers use NPM poisoning to inject malicious SVG and trick DApp users into signing through XSS pop-ups to steal coins - CoinFeed
Time 01:20

SlowMist: Attackers use NPM poisoning to inject malicious SVG and trick DApp users into signing through XSS pop-ups to steal coins

September 17, 2025
CoinFeed News

SlowMist Technology's Chief Information Security Officer, 23pds, posted on the X platform that attackers recently poisoned the NPM supply chain, replacing the SVG referenced by the decentralized platform with an embedded malicious script file. They then exploited SVG's XSS pop-up window to trick DApp users into signing and stealing their assets. Please pay attention to security.

Back to News Feed