Odaily Planet Daily News AdsPower security team transparently disclosed an intrusion incident on January 24. Hackers tampered with some third-party encrypted wallet plug-ins in AdsPower fingerprint browser by spreading malicious code. AdsPower has fixed the vulnerability and strengthened system security. At the same time, it has reported to the Singapore authorities and is actively cooperating with the police investigation.
According to official disclosure, from January 21 to 22, a small number of users reported that they could not install or update the MetaMask plug-in. On January 23, the technical team found that the plug-in download link was abnormal and changed it to the official download address. On January 24, AdsPower detected that the plug-in had been tampered with, and then deleted the malicious plug-in package, repaired the download link, and asked affected users to reinstall the plug-in to ensure safety.
Internal investigations show that attackers took advantage of vulnerabilities in third-party technical service systems to upload and spread malicious versions of MetaMask plug-ins, which may cause the cache information of user wallet plug-ins to be leaked. At present, AdsPower has upgraded the application center plug-in download mode, and will further strengthen network security, emergency response and supply chain security management in the future. Affected users can receive exclusive value-added service plans in the AdsPower client.