Hackers are exploiting a JavaScript library to plant crypto drainers

cointelegraphPublicado em 2025-12-15Última atualização em 2025-12-15

Resumo

A recent surge in crypto drainer attacks is exploiting a critical vulnerability (CVE-2025-55182) in the React JavaScript library, as reported by cybersecurity nonprofit Security Alliance (SEAL). The vulnerability, which allows unauthenticated remote code execution, was disclosed on December 3 after being discovered by a white hat hacker. Attackers are using this flaw to inject wallet-draining code into legitimate crypto websites, often tricking users into signing malicious transactions through fake pop-ups or reward offers. SEAL warns that affected websites may be flagged as phishing risks and urges all site owners to immediately scan their front-end code for suspicious or obfuscated scripts, unrecognized assets, and incorrect recipient addresses in signature requests. The React team has released a patch for the vulnerability and recommends that users of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack upgrade immediately. Apps not using React Server Components or a server are not affected.

There has been a recent uptick in crypto drainers being uploaded to websites through a vulnerability in the open-source front-end JavaScript library React, according to cybersecurity nonprofit Security Alliance (SEAL).

React is used for building user interfaces, especially in web applications. The React team disclosed on Dec. 3 that a white hat hacker, Lachlan Davidson, found a security vulnerability in its software that allowed unauthenticated remote code execution, which can allow an attacker to insert and run their own code.

According to SEAL, bad actors have been using the vulnerability, CVE-2025-55182, to secretly add wallet-draining code to crypto websites.

“We are observing a big uptick in drainers uploaded to legitimate crypto websites through exploitation of the recent React CVE. All websites should review front-end code for any suspicious assets NOW,” the SEAL Team said.

“The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature.”

Wallet drainers typically dupe users into signing a transaction through methods such as a sham pop-up offering rewards or similar tactics.

Source: Security Alliance

Websites with phishing warning should check code

Affected websites may have been suddenly flagged as a possible phishing risk without explanation, according to the SEAL Team. They recommend website hosts take precautions to ensure there are no hidden drainers that could put users at risk.

“Scan host for CVE-2025-55182. Check if your front-end code is suddenly loading assets from hosts you do not recognize. Check if any of the scripts loaded by your front end code are obfuscated JavaScript. Inspect if the wallet is showing the correct recipient on the signature signing request,” they said.

Related: North Korean ‘fake Zoom’ crypto hacks now a daily threat: SEAL

“If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal,” the SEAL Team added.

React has released a fix for the vulnerability

The React team published a fix for CVE-2025-55182 on Dec. 3 and advises anyone using the react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack, to upgrade immediately and close the vulnerability.

“If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability,” the team added.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Leituras Relacionadas

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

The CLARITY Act, which passed the House in July 2025 with strong bipartisan support (294-134), faces a critical juncture in the Senate. The Senate Banking Committee is expected to hold a markup soon, but key issues remain unresolved, including stablecoin yield provisions, DeFi regulations, and securing full Republican committee support. Other contentious points involve the Blockchain Regulatory Certainty Act (BRCA), ethics amendments for government officials, and SEC-related matters. The legislative calendar is tight, with limited time before the midterm elections. If the committee markup is delayed beyond mid-May, the chances of passage in 2026 drop significantly. Senator Cynthia Lummis has warned that failure this year could delay comprehensive crypto market structure legislation until 2030 or later. Galaxy estimates the probability of the CLARITY Act becoming law in 2026 is only about 50%. The bill provides crucial regulatory clarity by defining jurisdictional boundaries between the SEC and CFTC, establishing a path for decentralization, and bringing digital commodity intermediaries under federal regulation. Its passage is seen as vital before potential power shifts in the next Congress, which could bring less favorable leadership to key committees. The timeline is compressed, and the bill must compete for floor time with other priorities like Iran authorization and DHS appropriations. Key hurdles include finalizing the stablecoin yield compromise text, addressing law enforcement concerns about BRCA, and navigating political dynamics around SEC nominations. The outcome of the Banking Committee markup and the level of bipartisan support will be critical indicators of its future success.

marsbitHá 2m

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

marsbitHá 2m

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

The CLARITY Act, which passed the U.S. House in July 2025 with strong bipartisan support (294-134), faces a critical juncture in the Senate. The Senate Banking Committee is expected to hold a markup soon, but key issues remain unresolved, including stablecoin yield provisions, DeFi regulations, and securing full Republican committee support. Additional challenges involve the Blockchain Regulatory Certainty Act (BRCA), ethics amendments for government officials, and SEC-related concerns. Galaxy estimates only a 50% chance of the bill becoming law in 2026. The tight legislative calendar, competing priorities like Iran military authorization and DHS appropriations, and the impending midterm elections create significant time pressure. If the bill is not passed before the new Congress convenes in 2027, comprehensive crypto market structure legislation could be delayed until 2030 or later, especially if leadership changes result in less favorable committee chairs. The act provides crucial regulatory clarity by defining the jurisdictional boundaries between the SEC and CFTC, establishing a path for decentralized networks to be classified as non-securities, and bringing digital commodity intermediaries under federal regulation. The outcome of ongoing Senate negotiations, particularly the release of revised text on stablecoin yields, will be a key indicator of its future prospects.

Odaily星球日报Há 12m

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

Odaily星球日报Há 12m

Four-Dimensional Resonance: Hong Kong Web3 Carnival Sub-Forum Co-Creates Blueprint for Global Financial New Infrastructure

The "Four-Dimensional Resonance: 2026 Global Financial New Infrastructure" forum, a core event of the Hong Kong Web3 Festival, was successfully held at the Hong Kong Convention and Exhibition Centre. Co-hosted by Web3Labs and DeShang Singularity Tech, with joint support from Bitroot, Injective, Microsoft, and Z Oracle, the event gathered policymakers, industry leaders, and investors to explore the integration and innovation of global financial infrastructure, focusing on RWA, AI, DeFi, and compliant payments. Policy speakers, including Hong Kong Legislative Council Member Mr. Wu Jiezhuang, South Korean National Assembly Member Mr. Min Byung-duk, and ACED Chairman Mr. Yun Seok-hun, emphasized the importance of cross-border regulatory collaboration and an open policy environment for fintech innovation. Web3Labs CEO Caspar and DeShang Singularity Tech CEO Chang Shuai highlighted Hong Kong’s role as a financial innovation center and the approaching "singularity moment" for global financial infrastructure. Technical insights were shared by MagnetX, Bitroot, Microsoft, and Injective on topics including AI Agent economies, the evolution of public blockchains, and AI’s transformative role in finance. Key partnerships and initiatives were launched: - GWDC 2026 Korea collaboration between Hong Kong and South Korea. - A strategic agreement between Web3Labs and Microsoft. - The launch of a public anti-fraud alliance by Z Oracle and partners. - The "Injective Rising Star" program to support AI and Web3 projects. Panel discussions delved into AI-driven smart payments, compliant cross-border transactions, and the fusion of RWA and DeFi. Participants agreed that integrating RWA with DeFi is crucial for the next stage of financial infrastructure, enabling a shift from physical to digital finance. The forum underscored Hong Kong’s pivotal role in advancing a globalized and sustainable Asian fintech ecosystem.

marsbitHá 21m

Four-Dimensional Resonance: Hong Kong Web3 Carnival Sub-Forum Co-Creates Blueprint for Global Financial New Infrastructure

marsbitHá 21m

Trading

Spot
Futuros

Artigos em Destaque

Como comprar CFG

Bem-vindo à HTX.com!Tornámos a compra de Centrifuge (CFG) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Centrifuge (CFG) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Centrifuge (CFG)Depois de comprar o teu Centrifuge (CFG), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Centrifuge (CFG)Transaciona facilmente Centrifuge (CFG) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

204 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.03.19

Como comprar CFG

O que é WL

I. Introdução ao ProjetoWorldLand é uma L2 ou side chain do Ethereum, concebida como uma solução de baixo para cima para melhorar o ecossistema Ethereum.II. Informação sobre o Token1) Informação BásicaNome do token: WL (WorldLand)III. Links RelacionadosWebsite:https://worldland.foundation/Exploradores:https://bscscan.com/address/0x8aaB31fbc69C92fa53f600910Cf0f215531F8239Redes Sociais:https://x.com/WorldLand_space Nota: A introdução ao projeto provém dos materiais publicados ou fornecidos pela equipa oficial do projeto, que é apenas para referência e não constitui aconselhamento de investimento. A HTX não se responsabiliza por quaisquer perdas diretas ou indiretas resultantes.

173 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.03.28

O que é WL

Como comprar WL

Bem-vindo à HTX.com!Tornámos a compra de WorldLand (WL) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar WorldLand (WL) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu WorldLand (WL)Depois de comprar o teu WorldLand (WL), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona WorldLand (WL)Transaciona facilmente WorldLand (WL) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

235 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.03.28

Como comprar WL

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de A (A) são apresentadas abaixo.

活动图片