BTC $64,627.45 +1.00%
ETH $1,914.48 +1.17%
BNB $589.05 +3.81%
XRP $1.09 +1.99%
SOL $74.63 +1.97%
TRX $0.3286 +0.74%
DOGE $0.0704 +0.60%
ADA $0.1747 +7.61%
BCH $219.31 +4.53%
LINK $8.47 +2.56%
HYPE $54.02 -1.56%
AAVE $98.78 +0.67%
SUI $0.6969 +2.13%
XLM $0.1719 -0.31%
ZEC $475.18 +2.72%
BTC $64,627.45 +1.00%
ETH $1,914.48 +1.17%
BNB $589.05 +3.81%
XRP $1.09 +1.99%
SOL $74.63 +1.97%
TRX $0.3286 +0.74%
DOGE $0.0704 +0.60%
ADA $0.1747 +7.61%
BCH $219.31 +4.53%
LINK $8.47 +2.56%
HYPE $54.02 -1.56%
AAVE $98.78 +0.67%
SUI $0.6969 +2.13%
XLM $0.1719 -0.31%
ZEC $475.18 +2.72%

alert

All
Article
Flash

Security Alert: 30 malicious npm packages disguised as trading bot repositories, targeting the theft of developer keys and mnemonic phrases

SlowMist issued a security alert, detecting a coordinated malicious npm supply chain attack. The attackers utilized fake trading bot repositories and DeFi-themed npm packages to deploy JavaScript information stealers, targeting npm users, DeFi developers, and trading bot users.This attack involved 30 malicious npm packages, among which stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository presented approximately 2300 highly homogeneous bulk-generated forks, mostly concentrated under the poly-stocks account, with signals being exceptionally clear. The sensitive data that attackers could steal is extensive, including cryptocurrency wallet libraries, browser cookies and saved passwords, browsing history, developer credentials, shell history, password manager libraries, private keys, mnemonic phrases, and API tokens exposed in source code.SlowMist recommends that developers immediately remove the affected npm packages, audit package.json and package-lock.json, and check CI logs for any of the 30 malicious packages; consider any system that has executed npm install as potentially compromised, rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.

The Ministry of Industry and Information Technology of China issued a risk alert regarding the timely update of specific iOS versions to prevent the exploitation of vulnerabilities

The Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology of China has monitored and found that attackers are using exploit tools targeting Apple Inc.'s terminal products to carry out cyber attack activities, which can lead to serious harms such as information theft and system control. The affected range includes Apple terminal products such as iPhone and iPad running iOS 13 to 17.2.1.Attackers induce users to use the Safari browser to visit web pages containing malicious code through methods such as SMS, email, or web poisoning, comprehensively utilizing security vulnerabilities present in the terminal devices to implant remote control Trojans into the victim's terminal products, stealing sensitive user information, gaining maximum privileges, and taking control.It is recommended that users of Apple terminal products conduct risk assessments, and promptly fix vulnerabilities through version upgrades and patch installations (refer to the Apple Security Updates). Pay attention to system update notifications and the latest security update announcements released by Apple, upgrade to the latest secure version in a timely manner, strengthen security awareness, avoid clicking on unknown links, and prevent the risk of cyber attacks.
app_icon
ChainCatcher Building the Web3 world with innovations.