According to reports from Wu, the non-profit cybersecurity organization Security Alliance (SEAL) stated that recently hackers have exploited a security vulnerability in the open-source front-end JavaScript library React, implanting a program to empty cryptocurrency wallets into websites, with a noticeable increase in attack activities.
The React team disclosed on December 3 that a white-hat hacker discovered a security vulnerability in their software, allowing attackers to remotely execute code insertion and run malicious code. SEAL warned that this attack is not only targeting Web3 projects; all websites may be affected, urging users to remain vigilant when signing any authorization signatures.
