Thursday, July 30, 2026
  • Login
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
CRYPTO MARKETCAP
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

Second JavaScript Exploit in Four Months Exposes Crypto Sites to Wallet Drainers

by SB Crypto Guru News
December 15, 2025
in Crypto Updates
Reading Time: 3 mins read
0 0
A A
0


A newly discovered loophole in one of the web’s most
used development tools is giving hackers a new way to drain cryptocurrency
wallets.

Cybersecurity researchers have reported a surge in
malicious code uploaded to legitimate websites through a vulnerability in the
popular JavaScript library React, a tool used by countless crypto platforms
for their front-end systems.

Crypto Drainer Attacks Surge via React Flaw

According to Security Alliance (SEAL), a nonprofit
cybersecurity organization, criminals are actively exploiting a recently
disclosed React vulnerability labeled CVE-2025-55182.

Crypto Drainers using React CVE-2025-55182We are observing a big uptick in drainers uploaded to legitimate (crypto) websites through exploitation of the recent React CVE.All websites should review front-end code for any suspicious assets NOW.

— Security Alliance (@_SEAL_Org) December 13, 2025

“We are observing a big uptick in drainers uploaded to
legitimate crypto websites through exploitation of the recent React CVE,” SEAL
stated on X (formerly Twitter). “All websites should review front-end code for
any suspicious assets NOW.”

The flaw enables unauthenticated remote code
execution, allowing attackers to secretly inject wallet-draining scripts into
websites. The malicious code tricks users into approving fake transactions via
deceptive pop-ups or reward prompts.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

SEAL cautioned that some compromised sites may be
unexpectedly flagged as phishing risks. The organization advised web
administrators to conduct immediate security audits to catch any injected
assets or obfuscated JavaScript.

“If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal.

The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature,” SEAL urged.

Scan host for CVE-2025-55182Check if your FE code is suddenly loading assets from hosts you do not recognizeCheck if any of the “Scripts” loaded by your FE code are obfuscated JavaScriptInspect if the wallet is showing the correct recipient on the signature signing request

— Security Alliance (@_SEAL_Org) December 13, 2025

Phishing Flags and Hidden Drainers

The group warned that developers who find their
projects mistakenly blocked as phishing pages should inspect their code first
before appealing the warning.

In September, a major software supply-chain attack infiltrated JavaScript packages, raising the risk that cryptocurrency users could be
exposed to theft.

The incident involved the compromise of a reputable
developer’s account on the Node Package Manager platform, allowing attackers to
distribute malicious code through packages that have been downloaded more than
one billion times.

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

“There’s a large-scale supply chain attack in
progress: the NPM account of a reputable developer has been compromised,”
Guillemet explained. “The affected packages have already been downloaded over 1
billion times, meaning the entire JavaScript ecosystem may be at risk.”

This article was written by Jared Kirui at www.financemagnates.com.



Source link

Tags: Bitcoin NewsCryptoCrypto NewsCrypto UpdatesDrainersexploitexposesJavaScriptLatest News on CryptoMonthsSB Crypto Guru NewssitesWallet
Previous Post

Pussy Riot branded ‘extremist organisation’ by Russian court – The Art Newspaper

Next Post

Geode Lists GEODE Coin on BitMart.com as Part of Ongoing Decentralized Infrastructure Expansion

Related Posts

Hyperscale Data Sells 100 BTC to Fuel B AI Data Center

Hyperscale Data Sells 100 BTC to Fuel $3B AI Data Center

by SB Crypto Guru News
July 30, 2026
0

Key TakeawaysHyperscale Data sold about 100 bitcoin on July 30, 2026, worth roughly $6.5 million at the time.Alliance Cloud Services’...

DOJ Indicts Crypto Investor Over Alleged  Million Fraud Targeting Dozens of Victims – Bitcoin News

DOJ Indicts Crypto Investor Over Alleged $20 Million Fraud Targeting Dozens of Victims – Bitcoin News

by SB Crypto Guru News
July 30, 2026
0

Key TakeawaysFederal prosecutors allege a crypto investment scheme caused about $20 million in investor losses.The 29-count indictment includes wire fraud,...

TradFi Perpetuals Outpace Spot RWAs Eightfold on Crypto Exchanges

TradFi Perpetuals Outpace Spot RWAs Eightfold on Crypto Exchanges

by SB Crypto Guru News
July 29, 2026
0

Trading in traditional financial assets is expanding across the crypto exchanges tracked by CoinGecko, but most activity is not taking...

SBI Targets T On-Chain Finance Market With Canton Network Expansion and New Digital Unit

SBI Targets $6T On-Chain Finance Market With Canton Network Expansion and New Digital Unit

by SB Crypto Guru News
July 29, 2026
0

Key Takeaways:SBI Holdings has changed the name of its company SBI Security Solutions to SBI Digital Practice to favour on-chain...

Ondo Network Goes Live, Bringing Near-CEX Speed and Verifiable Onchain Execution

Ondo Network Goes Live, Bringing Near-CEX Speed and Verifiable Onchain Execution

by SB Crypto Guru News
July 29, 2026
0

Key Takeaways:Ondo Finance has launched the Ondo Network, a new execution layer designed for open financial markets.It is a network...

Load More
Next Post
Geode Lists GEODE Coin on BitMart.com as Part of Ongoing Decentralized Infrastructure Expansion

Geode Lists GEODE Coin on BitMart.com as Part of Ongoing Decentralized Infrastructure Expansion

Bitcoin Price Bleeds Below ,000 After Grim Weekend

Bitcoin Price Bleeds Below $89,000 After Grim Weekend

Facebook Twitter LinkedIn Tumblr RSS

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.