A newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets. Cybersecurity researchersA newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets. Cybersecurity researchers

Second JavaScript Exploit in Four Months Exposes Crypto Sites to Wallet Drainers

A newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets.

Cybersecurity researchers have reported a surge in malicious code uploaded to legitimate websites through a vulnerability in the popular JavaScript library React — a tool used by countless crypto platforms for their front-end systems.

Crypto Drainer Attacks Surge via React Flaw

According to Security Alliance (SEAL), a nonprofit cybersecurity organization, criminals are actively exploiting a recently disclosed React vulnerability labeled CVE-2025-55182.

“We are observing a big uptick in drainers uploaded to legitimate crypto websites through exploitation of the recent React CVE,” SEAL stated on X (formerly Twitter). “All websites should review front-end code for any suspicious assets NOW.

  • HP CEO “Exposes” Ink Cartridge Vulnerability Triggering Legal Storm
  • Exness Rewards Up to $10,000 in New Bug Bounty Program
  • How to Increase Business Security Using a Honeypot

The flaw enables unauthenticated remote code execution, allowing attackers to secretly inject wallet-draining scripts into websites. The malicious code tricks users into approving fake transactions via deceptive pop-ups or reward prompts.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

SEAL cautioned that some compromised sites may be unexpectedly flagged as phishing risks. The organization advised web administrators to conduct immediate security audits to catch any injected assets or obfuscated JavaScript.

"If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal. The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature."

Phishing Flags and Hidden Drainers

The group warned that developers who find their projects mistakenly blocked as phishing pages should inspect their code first before appealing the warning.

The React development team confirmed on December 3 that it had patched the vulnerability after white hat hacker Lachlan Davidson privately reported the issue.

The fix affects the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages. The team urged all developers using these components to update immediately.

Market Opportunity
MetaDOS Logo
MetaDOS Price(SECOND)
$0,0000038
$0,0000038$0,0000038
0,00%
USD
MetaDOS (SECOND) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin (BTC) Rebounds Today: “This Level Must Be Broken for Major October Rally,” Says Analysis Firm

Bitcoin (BTC) Rebounds Today: “This Level Must Be Broken for Major October Rally,” Says Analysis Firm

The post Bitcoin (BTC) Rebounds Today: “This Level Must Be Broken for Major October Rally,” Says Analysis Firm appeared on BitcoinEthereumNews.com. QCP Capital announced that cryptocurrency markets are showing signs of recovery after last week’s selling pressure, paving the way for an “October rally.” The company’s report noted that Bitcoin (BTC) rose to $112,000 and Ethereum (ETH) to $4,100. Spot prices remained stable over the weekend, despite significant ETF outflows last Friday, suggesting that selling pressure was absorbed more strongly than expected. QCP Capital argued that quarter-end liquidations were the main driver of these outflows and that this week’s ETF flows will determine the direction of institutional demand. The report revealed that despite a challenging month, Bitcoin closed September with a gain of more than 3%. Analysts noted that the market is preparing for the seasonal rally known as “Uptober,” and that it is critical for BTC to surpass the $115,000 level to confirm the uptrend. Cautious optimism is prevailing in the options market. According to QCP Capital, investor confidence is slowly returning, bearish sentiment is diminishing, and open interest in both Bitcoin and Ethereum is beginning to stabilize. This suggests that a potential October rally is starting to be factored in among investors, according to the analyst firm. *This is not investment advice. Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data! Source: https://en.bitcoinsistemi.com/bitcoin-btc-rebounds-today-this-level-must-be-broken-for-major-october-rally-says-analysis-firm/
Share
BitcoinEthereumNews2025/09/29 22:35
WIF Price Prediction: Targeting $0.48 Recovery Within 2 Weeks as MACD Shows Bullish Divergence

WIF Price Prediction: Targeting $0.48 Recovery Within 2 Weeks as MACD Shows Bullish Divergence

The post WIF Price Prediction: Targeting $0.48 Recovery Within 2 Weeks as MACD Shows Bullish Divergence appeared on BitcoinEthereumNews.com. James Ding Dec 16
Share
BitcoinEthereumNews2025/12/17 17:32
OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

PANews reported on September 17th that on-chain sleuth ZachXBT tweeted that OpenVPP ( $OVPP ) announced this week that it was collaborating with the US government to advance energy tokenization. SEC Commissioner Hester Peirce subsequently responded, stating that the company does not collaborate with or endorse any private crypto projects. The OpenVPP team subsequently hid the response. Several crypto influencers have participated in promoting the project, and the accounts involved have been questioned as typical influencer accounts.
Share
PANews2025/09/17 23:58