Apifox desktop client suffers from a supply chain attack, malicious code can steal credentials and execute commands remotely
Mar 26, 2026 13:10:01
According to Slow Fog monitoring, the Apifox desktop client has encountered a supply chain attack, with front-end script files hosted on its official CDN being injected with highly obfuscated malicious JavaScript code.
Affected users may face risks such as credential theft, sensitive data leakage, and remote command execution, with the malicious code executing automatically and being highly concealed. Slow Fog recommends that users immediately revoke all Tokens, reset passwords, log out and log back in to invalidate sessions, block the *.apifox.it.com domain, clear local storage, and review API logs and abnormal activities.
Latest News
ChainCatcher
Mar 26, 2026 14:41:42
ChainCatcher
Mar 26, 2026 14:06:00
ChainCatcher
Mar 26, 2026 14:04:56
ChainCatcher
Mar 26, 2026 14:04:46
ChainCatcher
Mar 26, 2026 14:01:53












