Threats Tagged 'mal-2026-10497'
View all threats tagged with 'mal-2026-10497'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-10497'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in ddok-modal (npm) 0 The ddok-modal npm package is a malicious React component that impersonates wallet connection modals for popular cryptocurrency wallets such as MetaMask, Phantom, Rabby, TronLink, Bitget, Coinbase, and Solflare. It captures user credentials including passwords and secret recovery phrases by sending them to attacker-controlled endpoints. The package collects additional user information like IP address and geolocation to enhance the attack. This malicious behavior occurs in version 1.0.0 of ddok-modal. Any web application embedding this component risks exposing its users' sensitive wallet credentials to attackers. Join the discussion | GCVE Database | 07/13/2026, 21:44:42 UTC Added: 07/14/2026, 09:21:20 UTC |
Showing 1 to 1 of 1 result