Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the bitensor
package.
bitensor is a malicious package. This package contains malicious code, and its content was removed from the official package manager. The package appears to be part of a typosquatting campaign targeting the Bittensor ecosystem. The goal of the attackers is to steal cryptocurrency from users' wallets.
The malicious packages mimic legitimate Bittensor libraries. When a user unknowingly installs one of these packages and attempts to stake their cryptocurrency, a modified function diverts the user's entire wallet balance to an address controlled by the attacker. The attack is designed to be stealthy, as it occurs during what appears to be a normal staking operation.