PieDAO: Zapper and Sushi front-end have been attacked.
BlockBeats reported on December 14th that PeckShieldAlert, a community contributor, reported on social media that the front-end of Zapper and Sushi has been compromised. In response, Matthew Lilley, CTO of Sushi, stated that LedgerHQ/connect-kit loaded JavaScript from a CDN, and their CDN account has been breached, injecting malicious JavaScript into multiple dApps.
As previously reported by BlockBeats, Matthew Lilley, CTO of Sushi, issued a warning on social media advising users not to interact with any dApps until further notice. A commonly used Web3 connector appears to have been compromised, allowing for the injection of malicious code that affects numerous dApps.