**Major npm Package Attack Hits 47M Weekly Downloads**
The popular npm package **"error-ex"** with 47 million weekly downloads was compromised by attackers. The malicious code redirected MetaMask transactions to hacker-controlled addresses using visually similar addresses to deceive users during transaction signing.
**Cian Platform Status:**
- ✅ **All systems safe** - comprehensive audit of 5 frontend projects found zero compromised packages
- ✅ **Extra precautions taken** - all package versions locked, updates paused until threat clears
**Security Recommendations:**
- **Hardware wallet users:** Enable clear signing, verify every address digit-by-digit
- **Software wallet users:** Consider pausing on-chain transfers temporarily
- **Developers:** Check dependency versions immediately, rollback or lock to safe versions
Alephium also confirmed their wallets remain unaffected by the supply chain attack.