SlowMist Yuxian posted on X: "Pay attention to @solana/web3.js supply chain poisoning. The known 1.95.6 and 1.95.7 versions have backdoor code that will steal user private keys. The new version no longer has this risk. Well-known wallets have not discovered this risk, but the real attack has occurred.
It is speculated that third-party private key-related tools (including bots) that updated dependent packages in a timely manner may have been infected, because the poisoned version only survived for a few hours and was quickly discovered and removed from the shelves. If you use this package, pay attention to investigation."