Inject malicious script

Attackers inject malicious scripts to hacked websites to get to the funds of the users e.g. by manipulating transactions or redirecting them to a malicious website. An example of an attack via injected script within the cryptocurrency space can be found in the Badger DAO hack.
Sub techniques (1)
IDName
RD07 Create script to exploit vulnerabilities
IDMitigationDescription
M22Check transaction address (public key) Using a service users/investors should check the transaction address everytime since attackers could inject a script (or attack the smart contract) and divert coins/tokens to their addresses.