• bitcoinBitcoin (BTC) $ 119,869.00
  • ethereumEthereum (ETH) $ 3,472.26
  • xrpXRP (XRP) $ 3.49
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 722.87
  • solanaSolana (SOL) $ 176.17
  • usd-coinUSDC (USDC) $ 0.999903
  • dogecoinDogecoin (DOGE) $ 0.218542
  • staked-etherLido Staked Ether (STETH) $ 3,466.26
  • tronTRON (TRX) $ 0.316406
  • cardanoCardano (ADA) $ 0.830515
  • stellarStellar (XLM) $ 0.506743
  • hyperliquidHyperliquid (HYPE) $ 46.23
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 119,715.00
  • wrapped-stethWrapped stETH (WSTETH) $ 4,188.47
  • suiSui (SUI) $ 4.05
  • hedera-hashgraphHedera (HBAR) $ 0.283026
  • chainlinkChainlink (LINK) $ 17.75
  • bitcoin-cashBitcoin Cash (BCH) $ 501.48
  • avalanche-2Avalanche (AVAX) $ 23.07
  • wrapped-eethWrapped eETH (WEETH) $ 3,721.04
  • shiba-inuShiba Inu (SHIB) $ 0.000015
  • leo-tokenLEO Token (LEO) $ 8.93
  • wethWETH (WETH) $ 3,472.77
  • the-open-networkToncoin (TON) $ 3.19
  • litecoinLitecoin (LTC) $ 102.46
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • usdsUSDS (USDS) $ 0.999892
  • whitebitWhiteBIT Coin (WBT) $ 45.50
  • polkadotPolkadot (DOT) $ 4.26
  • moneroMonero (XMR) $ 338.29
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 119,752.00
  • pepePepe (PEPE) $ 0.000013
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 4.77
  • uniswapUniswap (UNI) $ 8.92
  • aaveAave (AAVE) $ 320.36
  • bittensorBittensor (TAO) $ 426.79
  • crypto-com-chainCronos (CRO) $ 0.118080
  • daiDai (DAI) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.82
  • aptosAptos (APT) $ 5.30
  • pi-networkPi Network (PI) $ 0.439941
  • ondo-financeOndo (ONDO) $ 1.04
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • ethereum-classicEthereum Classic (ETC) $ 20.21
  • internet-computerInternet Computer (ICP) $ 5.72
  • jito-staked-solJito Staked SOL (JITOSOL) $ 212.83
  • algorandAlgorand (ALGO) $ 0.326521
  • okbOKB (OKB) $ 47.16
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bonkBonk (BONK) $ 0.000036
  • mantleMantle (MNT) $ 0.793236
  • kaspaKaspa (KAS) $ 0.095827
  • ethenaEthena (ENA) $ 0.383231
  • arbitrumArbitrum (ARB) $ 0.448581
  • vechainVeChain (VET) $ 0.026403
  • cosmosCosmos Hub (ATOM) $ 4.86
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • render-tokenRender (RENDER) $ 4.14
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.236945
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,480.23
  • sei-networkSei (SEI) $ 0.350764
  • official-trumpOfficial Trump (TRUMP) $ 10.01
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.770195
  • worldcoin-wldWorldcoin (WLD) $ 1.12
  • fasttokenFasttoken (FTN) $ 4.51
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030720
  • gatechain-tokenGate (GT) $ 16.08
  • filecoinFilecoin (FIL) $ 2.72
  • susdssUSDS (SUSDS) $ 1.06
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 119,526.00
  • pump-funPump.fun (PUMP) $ 0.004882
  • binance-staked-solBinance Staked SOL (BNSOL) $ 187.19
  • spx6900SPX6900 (SPX) $ 1.81
  • skySky (SKY) $ 0.078338
  • quant-networkQuant (QNT) $ 113.64
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,635.33
  • jupiter-exchange-solanaJupiter (JUP) $ 0.544203
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,955.87
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.93
  • kucoin-sharesKuCoin (KCS) $ 11.88
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998909
  • flare-networksFlare (FLR) $ 0.021173
  • usdtbUSDtb (USDTB) $ 0.999884
  • fartcoinFartcoin (FARTCOIN) $ 1.43
  • celestiaCelestia (TIA) $ 1.96
  • injective-protocolInjective (INJ) $ 14.04
  • usdt0USDT0 (USDT0) $ 1.00
  • curve-dao-tokenCurve DAO (CRV) $ 0.991680
  • blockstackStacks (STX) $ 0.848825
  • nexoNEXO (NEXO) $ 1.34
  • story-2Story (IP) $ 4.49
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,650.41
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,713.15
  • flokiFLOKI (FLOKI) $ 0.000131
  • optimismOptimism (OP) $ 0.721784
  • xdce-crowd-saleXDC Network (XDC) $ 0.078155
  • sonic-3Sonic (S) $ 0.380107
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.81
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,744.06
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,656.58
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 119,810.00
  • dogwifcoindogwifhat (WIF) $ 1.07
  • immutable-xImmutable (IMX) $ 0.556885
  • the-graphThe Graph (GRT) $ 0.106025
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 119,669.00
  • kaiaKaia (KAIA) $ 0.163507
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 197.38
  • iotaIOTA (IOTA) $ 0.244069
  • wbnbWrapped BNB (WBNB) $ 723.87
  • lido-daoLido DAO (LDO) $ 1.05
  • clbtcclBTC (CLBTC) $ 122,309.00
  • pax-goldPAX Gold (PAXG) $ 3,346.29
  • ethereum-name-serviceEthereum Name Service (ENS) $ 27.75
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.61
  • vaultaVaulta (A) $ 0.569801
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • tokenize-xchangeTokenize Xchange (TKX) $ 10.92
  • msolMarinade Staked SOL (MSOL) $ 229.66
  • paypal-usdPayPal USD (PYUSD) $ 0.999871
  • theta-tokenTheta Network (THETA) $ 0.866195
  • galaGALA (GALA) $ 0.018673
  • jasmycoinJasmyCoin (JASMY) $ 0.017316
  • tether-goldTether Gold (XAUT) $ 3,341.24
  • the-sandboxThe Sandbox (SAND) $ 0.325503
  • aerodrome-financeAerodrome Finance (AERO) $ 0.919563
  • raydiumRaydium (RAY) $ 2.93
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,714.16
  • super-oethSuper OETH (SUPEROETH) $ 3,474.99
  • pyth-networkPyth Network (PYTH) $ 0.129178
  • zcashZcash (ZEC) $ 45.47
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,633.00
  • ousgOUSG (OUSG) $ 111.83
  • tezosTezos (XTZ) $ 0.670540
  • bittorrentBitTorrent (BTT) $ 0.00000070
  • jito-governance-tokenJito (JTO) $ 1.94
  • saros-financeSaros (SAROS) $ 0.261557
  • pendlePendle (PENDLE) $ 4.17
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998653
  • morphoMorpho (MORPHO) $ 2.07
  • tbtctBTC (TBTC) $ 119,576.00
  • flowFlow (FLOW) $ 0.411567
  • heliumHelium (HNT) $ 3.55
  • falcon-financeFalcon USD (USDF) $ 1.00
  • walrus-2Walrus (WAL) $ 0.461764
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • chain-2Onyxcoin (XCN) $ 0.018533
  • mog-coinMog Coin (MOG) $ 0.000002
  • decentralandDecentraland (MANA) $ 0.327821
  • memecoreMemeCore (M) $ 0.371401
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,471.58
  • based-brettBrett (BRETT) $ 0.060700
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 119,213.00
  • newton-projectAB (AB) $ 0.008680
  • telcoinTelcoin (TEL) $ 0.006389
  • usual-usdUsual USD (USD0) $ 0.997741
  • thorchainTHORChain (RUNE) $ 1.65
  • bitcoin-svBitcoin SV (BSV) $ 29.12
  • coredaoorgCore (CORE) $ 0.563381
  • reserve-rights-tokenReserve Rights (RSR) $ 0.009707
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 119,581.00
  • usddUSDD (USDD) $ 1.00
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.219669
  • ether-fiEther.fi (ETHFI) $ 1.33
  • wrapped-hypeWrapped HYPE (WHYPE) $ 46.11
  • stader-ethxStader ETHx (ETHX) $ 3,686.71
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,472.31
  • apecoinApeCoin (APE) $ 0.676588
  • beldexBeldex (BDX) $ 0.073971
  • conflux-tokenConflux (CFX) $ 0.101815
  • ripple-usdRipple USD (RLUSD) $ 0.999904
  • savings-daiSavings Dai (SDAI) $ 1.16
  • deepDeepBook (DEEP) $ 0.204535
  • starknetStarknet (STRK) $ 0.140807
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,829.84
  • dydx-chaindYdX (DYDX) $ 0.663365
  • build-onBUILDon (B) $ 0.492946
  • true-usdTrueUSD (TUSD) $ 1.00
  • aioz-networkAIOZ Network (AIOZ) $ 0.418586
  • arweaveArweave (AR) $ 7.43
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.53
  • neoNEO (NEO) $ 6.81
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,457.44
  • elrond-erd-2MultiversX (EGLD) $ 16.63
  • syrupMaple Finance (SYRUP) $ 0.438856
  • compound-governance-tokenCompound (COMP) $ 50.01
  • kavaKava (KAVA) $ 0.434635
  • venomVenom (VENOM) $ 0.222805
  • swethSwell Ethereum (SWETH) $ 3,800.30
  • apenftAPENFT (NFT) $ 0.00000047
  • 1inch1inch (1INCH) $ 0.326487
  • staked-hypeStaked HYPE (STHYPE) $ 46.06
  • dexeDeXe (DEXE) $ 7.90
  • axie-infinityAxie Infinity (AXS) $ 2.65
  • zksyncZKsync (ZK) $ 0.060757
  • wormholeWormhole (W) $ 0.094189
  • ecasheCash (XEC) $ 0.000022

Malicious Pull Request Inserted Into Ethereum Code Extension: Research

0 7

Malicious Pull Request Inserted Into Ethereum Code Extension: Research

A hacker inserted a malicious pull request into a code extension for Ethereum developers, according to researchers at cybersecurity firm ReversingLabs.

The malicious code was inserted into an update for ETHcode, an open source suite of tools used by Ethereum devs to build and deploy EVM-compatible smart contracts and dapps.

A blog by ReversingLabs reveals that two malicious lines of code were buried in a GitHub pull request that comprised 43 commits and 4,000 updated lines, and that concerned itself primarily with adding a new testing framework and capabilities.

The update was added to GitHub on June 17 by Airez299, a user who had no prior history.

The pull request was analysed by GitHub’s AI reviewer and by members of 7finney, the group responsible for creating ETHcode.

Only minor changes were requested, with neither 7finney nor the AI scanner finding anything suspicious.

Airez299 was able to obscure the nature of the first malicious line of code by giving it a similar name to that of a preexisting file, while also obfuscating and jumbling the code itself, making it harder to read.

The second line of code functions to activate the first, which according to ReversingLabs ultimately has the purpose of creating an automated function (a Powershell) that downloads and operates a batch script from a public file-hosting service.

ReversingLabs is still investigating what exactly this script does, although it’s working under the assumption that it’s “intended to steal crypto assets stored on the victim’s machine or, alternatively, compromise the Ethereum contracts under development by users of the extension.”

Speaking to Decrypt, the blog’s author Petar Kirhmajer reported that ReversingLabs has no indication or evidence that the malicious code has actually been used to steal tokens or data.

However, Kirhmajer writes in the blog that ETHcode has 6,000 installs, and that the pull request—which would have been rolled out as part of an automatic update—may have spread “to thousands of developer systems.”

This is potentially concerning, and some developers suggest that this kind of exploit happens a lot in crypto, given that the industry relies heavily on open source development.

“Too much code and not enough eyes on it.”

According to Ethereum developer and NUMBER GROUP co-founder Zak Cole, many developers install open source packages without checking them properly.

“It’s way too easy for someone to slip in something malicious,” he told Decrypt. “Could be an npm package, a browser extension, whatever.”

Recent high-profile examples of this include the Ledger Connect Kit exploit from December 2023, as well as the discovery last December of malware in Solana’s web3.js open source library.

“There’s too much code and not enough eyes on it,” adds Cole. “Most people just assume stuff is safe because it’s popular or been around a while, but that doesn’t mean anything.”

Cole affirms that, while this kind of thing is not particularly new, “the addressable surface of attack is spreading” because more and more developers are using open source tools.

“Also, keep in mind that there are entire warehouses full of DPRK operatives whose full time job is to execute these exploits,” he says.

While Cole suggests that there is probably more malicious code lurking around than many devs probably realise, Kirhmajer told Decrypt that, in his estimation, “successful attempts are very rare.”

This leads to the question of what developers can do to reduce their chances of using compromised code, with ReversingLabs recommending that they verify the identity and history of contributors before downloading anything.

The firm also suggested that devs review files such as package.json in order to evaluate new dependencies, which is something that Zak Cole also advocates.

“What helps is locking down your dependencies so you’re not pulling in random new stuff every time you build,” he said.

Cole also recommended using tools that scan for weird behavior or sketchy maintainers, while also looking out for any packages that might suddenly change hands or update out of the blue.

“Also don’t run signing tools or wallets on the same machine you use to build stuff,” he concluded. “Just assume nothing is safe unless you’ve checked it or sandboxed it.”

Source

Leave A Reply

Your email address will not be published.