SlowMist: Apifox desktop client targeted in supply chain attack, malicious code can steal credentials and execute remote commands

robot
Abstract generation in progress

Golden Finance reports that on March 26, according to SlowMist monitoring, the Apifox desktop client was targeted in a supply chain attack, with its official CDN-hosted front-end script files injected with highly obfuscated malicious JavaScript code.
Affected users may face risks such as credential theft, sensitive data leaks, and remote command execution, with the malicious code executing automatically and remaining highly covert. SlowMist recommends users immediately revoke all tokens, reset passwords, log out and log back in to invalidate sessions, block the *.apifox.it.com domain, clear local storage, and review API logs and abnormal activities.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin