X @ShapeShift
ShapeShift·2025-09-08 19:40
Regarding the recent NPM supply-chain attack:Both ShapeShift and ShapeShift Mobile users are completely unaffected by the vulnerability.We've confirmed across the source code that none of the affected package-versions exist in any ShapeShift product.Users safu 🦊Charles Guillemet (@P3b7_):🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ...