[Subscribe Now] Track A-Level Transparency Project Biweekly Report and Discover the Top 1% of Projects
API Download the RootData App

Apifox desktop client suffers from a supply chain attack, malicious code can steal credentials and execute commands remotely

Mar 26, 2026 13:10:01

Share to

According to Slow Fog monitoring, the Apifox desktop client has encountered a supply chain attack, with front-end script files hosted on its official CDN being injected with highly obfuscated malicious JavaScript code.

Affected users may face risks such as credential theft, sensitive data leakage, and remote command execution, with the malicious code executing automatically and being highly concealed. Slow Fog recommends that users immediately revoke all Tokens, reset passwords, log out and log back in to invalidate sessions, block the *.apifox.it.com domain, clear local storage, and review API logs and abnormal activities.

Recent Fundraising

More
$6M Dec 1, 2025
$63M Mar 26
$2M Mar 25

New Tokens

More
Mar 23
edgeX EDGE
Mar 19
Mar 18

Latest Updates on 𝕏

More
Mar 25
Mar 25