What happened. In short, @Ledger made a chain of terrible blunders. They are loading JS from a CDN.

14 Dec 2023, 13:08
What happened? In short, @Ledger made a chain of terrible blunders. 1. They are loading JS from a CDN. 2. They are not version locking loaded JS. 3. They had their CDN compromised. I would avoid using ANY dApps until their teams confirm that they have mitigated the attack.

Same news in other sources

1
BitBall
BitBallBTB #2461
Twitter
14 Dec 2023, 13:10
🚨 Urgent Security Alert 🚨 We've identified a critical issue the ledger connector has been compromised, potentially allowing the injection of malicious code affecting various dApps. 🔴 If you have the Sushi page open and see an unexpected 'Connect Wallet' pop-up, DO NOT…
Urgent Security Alert.
🚨 Urgent Security Alert 🚨 We've identified a critical issue the ledger connector has been compromised, potentially allowing the injection of malicious code affecting various dApps. 🔴 If you have the Sushi page open and see an unexpected 'Connect Wallet' pop-up, DO NOT…