DuckDB NPM Account Compromised, Leading to Malicious Software Release

SlowMist Technology’s Chief Information Security Officer, 23pds, revealed that the DuckDB NPM account was compromised earlier today. As a result, malicious versions of DuckDB and duckdb-wasm were released. These malicious software variations mirror the wallet-stealing malware identified in yesterday’s supply chain attack. Users are urged to be cautious and proactively implement security measures to mitigate potential risks.