icon

We found results for “

MSC-2025-7883

Date: September 8, 2025

proto-tinker-wc was compromised to include malicious code that targets browser-based web3 environments. The injected payload intercepts Ethereum and Solana wallet interactions, redirecting funds and approvals to attacker-controlled addresses. The compromise occurred after a maintainer’s account was accessed via phishing. We recommend removing the affected version from the codebase and downgrading to the last clean version 0.1.86, as there is no fix version

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Hidden Functionality

CWE-912

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us