After an internal review, we can confirm that Streamflow uses none of the affected versions of the impacted npm packages Streamflow users are not at risk and can keep using our dApp and SDK safely ✅

Charles Guillemet
@P3b7_
09-09
🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments