💥 Gate Square Event: #PTB Creative Contest# 💥
Post original content related to PTB, CandyDrop #77, or Launchpool on Gate Square for a chance to share 5,000 PTB rewards!
CandyDrop x PTB 👉 https://www.gate.com/zh/announcements/article/46922
PTB Launchpool is live 👉 https://www.gate.com/zh/announcements/article/46934
📅 Event Period: Sep 10, 2025 04:00 UTC – Sep 14, 2025 16:00 UTC
📌 How to Participate:
Post original content related to PTB, CandyDrop, or Launchpool
Minimum 80 words
Add hashtag: #PTB Creative Contest#
Include CandyDrop or Launchpool participation screenshot
🏆 Rewards:
🥇 1st
Recently, a major cybersecurity incident has shocked the entire tech community. A well-known JavaScript developer's npm account is suspected to have been targeted by a phishing attack, resulting in multiple popular Open Source packages being implanted with malicious code. The affected packages have a cumulative download count of over 1 billion times, which is astonishing in its scope.
The method of this attack is quite covert. The implanted malicious code can quietly alter the cryptocurrency transfer address without the user's knowledge. This means that when users make a blockchain transfer, the actual receiving address may be replaced with the attacker’s address, resulting in funds being stolen.
In the face of this serious security threat, experts recommend that users immediately take the following protective measures:
1. Suspend all non-essential on-chain transfers and signing operations, especially those involving browser wallets and Web DApps.
2. Carefully check and confirm whether the wallet and website you are using have been affected.
3. Closely monitor security announcements released by official sources and the community, and wait for confirmation on which versions are safe.
4. After ensuring safety, promptly update to a verified secure version.
For users who are not very familiar with the technical details, it can be simply understood as: someone has secretly replaced commonly used software components with a "virus" version. This "virus" will quietly change your cryptocurrency transfer address, sending money to hackers. Therefore, it is best to pause unnecessary cryptocurrency operations until the situation is clear to ensure the safety of funds.
This incident highlights the importance of supply chain security once again. Developers and users need to remain vigilant, regularly check and update their dependencies, and use security measures such as multi-factor authentication to protect their accounts. At the same time, this also reminds us to double-check transaction details when conducting cryptocurrency transactions to prevent potential financial losses.
As the situation develops, relevant parties are actively taking measures to repair this vulnerability and prevent similar incidents from occurring again. We will continue to monitor the progress of this event and update relevant information in a timely manner.