Binance Square
#npm

npm

20,408 views
35 Discussing
Block Cycle Hunter
·
--
Mysterious Fog latest alert: the npm supply chain suffers a large-scale intrusion ⚠️ The Keyv/Cacheable ecosystem has been targeted—attackers have published more than 2,000 malicious package versions, and keyv@6.0.0 has been confirmed to have a backdoor implanted. Keyv is a key-value storage abstraction library that supports multiple backends including Redis, SQLite, PostgreSQL, and MongoDB. It is downloaded about 127 million times per week, with a remarkably wide impact. The attack methods are highly similar to the earlier Shai-Hulud npm worm activity—highly automated and capable of large-scale replication. The main risks include: 🔴 Credential theft and environment variable leakage 🔴 Compromise of CI/CD keys 🔴 Deployment of remote malicious payloads 🔴 Lateral propagation through infected development environments Security recommendations: 1️⃣ Immediately identify and remove affected package versions 2️⃣ Upgrade to verified secure versions 3️⃣ Thoroughly review dependency lock files and build logs 4️⃣ Monitor suspicious outbound connections 5️⃣ Rotate all potentially exposed credentials Supply chain attacks often quietly infiltrate the development workflow. It is recommended that all teams—especially Web3 project teams—conduct an immediate self-audit and do not take this lightly. #供应链安全 #npm #网络安全
Mysterious Fog latest alert: the npm supply chain suffers a large-scale intrusion ⚠️

The Keyv/Cacheable ecosystem has been targeted—attackers have published more than 2,000 malicious package versions, and keyv@6.0.0 has been confirmed to have a backdoor implanted. Keyv is a key-value storage abstraction library that supports multiple backends including Redis, SQLite, PostgreSQL, and MongoDB. It is downloaded about 127 million times per week, with a remarkably wide impact.

The attack methods are highly similar to the earlier Shai-Hulud npm worm activity—highly automated and capable of large-scale replication. The main risks include:

🔴 Credential theft and environment variable leakage
🔴 Compromise of CI/CD keys
🔴 Deployment of remote malicious payloads
🔴 Lateral propagation through infected development environments

Security recommendations:
1️⃣ Immediately identify and remove affected package versions
2️⃣ Upgrade to verified secure versions
3️⃣ Thoroughly review dependency lock files and build logs
4️⃣ Monitor suspicious outbound connections
5️⃣ Rotate all potentially exposed credentials

Supply chain attacks often quietly infiltrate the development workflow. It is recommended that all teams—especially Web3 project teams—conduct an immediate self-audit and do not take this lightly.

#供应链安全 #npm #网络安全
The Mist Fog Security Team has just detected a serious malicious npm supply-chain attack targeting npm users and DeFi developers ⚠️ According to MistEye detection by Mist Fog, this is a coordinated attack. The attackers deploy JavaScript information-stealing tools by creating fake transaction-bot code repositories and DeFi-themed npm packages. So far, 30 malicious npm packages have been identified, including stake-math@3.5.4. Of particular note, one repository, donoaccestag/forex-mt5-trading-bot, depends on this malicious package, and the repository has already generated around 2,300 highly homogeneous forks—most likely batch-generated by the attacker—primarily under the poly-stocks account. Once your device is compromised, the attacker can steal: 🔴 Crypto wallet private keys and seed phrases 🔴 Browser cookies and saved passwords 🔴 Developer credentials and SSH keys 🔴 Shell history and API tokens 🔴 Sensitive information such as password manager data **Developers need to take these protections immediately:** 1️⃣ Remove all affected npm packages 2️⃣ Audit package.json and package-lock.json as well as CI logs 3️⃣ Any system that has run npm install should be considered potentially compromised 4️⃣ Promptly rotate exposed sensitive information such as wallet keys, npm tokens, and cloud credentials 5️⃣ Rebuild the development environment from a clean image There is no small matter in security. Supply-chain attacks have become increasingly frequent in recent years, and all DeFi developers need to stay vigilant! #npm #慢雾 #Supply Chain Security
The Mist Fog Security Team has just detected a serious malicious npm supply-chain attack targeting npm users and DeFi developers ⚠️

According to MistEye detection by Mist Fog, this is a coordinated attack. The attackers deploy JavaScript information-stealing tools by creating fake transaction-bot code repositories and DeFi-themed npm packages. So far, 30 malicious npm packages have been identified, including stake-math@3.5.4.

Of particular note, one repository, donoaccestag/forex-mt5-trading-bot, depends on this malicious package, and the repository has already generated around 2,300 highly homogeneous forks—most likely batch-generated by the attacker—primarily under the poly-stocks account.

Once your device is compromised, the attacker can steal:
🔴 Crypto wallet private keys and seed phrases
🔴 Browser cookies and saved passwords
🔴 Developer credentials and SSH keys
🔴 Shell history and API tokens
🔴 Sensitive information such as password manager data

**Developers need to take these protections immediately:**
1️⃣ Remove all affected npm packages
2️⃣ Audit package.json and package-lock.json as well as CI logs
3️⃣ Any system that has run npm install should be considered potentially compromised
4️⃣ Promptly rotate exposed sensitive information such as wallet keys, npm tokens, and cloud credentials
5️⃣ Rebuild the development environment from a clean image

There is no small matter in security. Supply-chain attacks have become increasingly frequent in recent years, and all DeFi developers need to stay vigilant!

#npm #慢雾 #Supply Chain Security
The Mist Security Team has just issued an alert, detecting a coordinated malicious supply-chain attack targeting npm users and DeFi developers ⚠️ According to monitoring by MistEye, the attackers have deployed JavaScript information-stealing tooling via fake transaction-bot code repositories and DeFi-themed npm packages. So far, 30 malicious npm packages have been identified, including stake-math@3.5.4, which has already appeared in the lockfile dependencies of a public code repository. Even more concerning is that the related anomalous repositories have generated around 2,300 highly homogeneous forks—most likely mass-produced by the attacker—mainly under the poly-stocks account. If you get compromised, the attacker can steal your: 🔴 Crypto wallet private keys and mnemonic phrases 🔴 Browser cookies, saved passwords, and browsing history 🔴 Developer credentials, shell history, and password manager data 🔴 Sensitive information such as API tokens in the source code All developers are advised to take immediate action: 1️⃣ Remove the affected npm packages 2️⃣ Audit package.json / package-lock.json and CI logs 3️⃣ Check systems that have run npm install, and promptly replace any exposed keys and credentials 4️⃣ Rebuild the affected environment from a clean image Supply-chain attacks are no longer new, but targeted attacks against crypto developers are becoming increasingly frequent. Please strengthen your security awareness and check your dependencies in time ❗️ #npm #供应链安全 #DeFi安全
The Mist Security Team has just issued an alert, detecting a coordinated malicious supply-chain attack targeting npm users and DeFi developers ⚠️

According to monitoring by MistEye, the attackers have deployed JavaScript information-stealing tooling via fake transaction-bot code repositories and DeFi-themed npm packages. So far, 30 malicious npm packages have been identified, including stake-math@3.5.4, which has already appeared in the lockfile dependencies of a public code repository.

Even more concerning is that the related anomalous repositories have generated around 2,300 highly homogeneous forks—most likely mass-produced by the attacker—mainly under the poly-stocks account.

If you get compromised, the attacker can steal your:
🔴 Crypto wallet private keys and mnemonic phrases
🔴 Browser cookies, saved passwords, and browsing history
🔴 Developer credentials, shell history, and password manager data
🔴 Sensitive information such as API tokens in the source code

All developers are advised to take immediate action:
1️⃣ Remove the affected npm packages
2️⃣ Audit package.json / package-lock.json and CI logs
3️⃣ Check systems that have run npm install, and promptly replace any exposed keys and credentials
4️⃣ Rebuild the affected environment from a clean image

Supply-chain attacks are no longer new, but targeted attacks against crypto developers are becoming increasingly frequent. Please strengthen your security awareness and check your dependencies in time ❗️

#npm #供应链安全 #DeFi安全
🚨 Security Alert: 30 malicious npm packages disguised as trading bots, specifically stealing developer keys and mnemonic phrases! #npm #DeFi
🚨 Security Alert: 30 malicious npm packages disguised as trading bots, specifically stealing developer keys and mnemonic phrases! #npm #DeFi
🚨 2,000 POISONED PACKAGES FLOOD $KEYV — 127M DOWNLOADS IN THE BLAST RADIUS! 💥 At 127M downloads a week, this isn't a bug — it's a weaponized breach with a huge blast radius. 🦈 The attacker flooded the Keyv/Cacheable ecosystem with 2,000+ malicious versions, including keyv@6.0.0, mirroring the Shai-Hulud worm's automation. 🔍 This is how projects get gutted from the inside: credential theft, CI/CD key leaks, remote payloads, lateral movement through dev environments. Every downstream app touching this library is exposed. 📊 If you hold keys or run build pipelines on Node.js, treat your dependencies as compromised until audited. Rotate credentials and inspect lock files now. ⚠️ 💬 Is your project's dependency tree clean, or are you one package away from a nightmare? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #KEYV #SupplyChainAttack #CryptoSecurity #CyberAlert #NPM 🔍 🛡️
🚨 2,000 POISONED PACKAGES FLOOD $KEYV — 127M DOWNLOADS IN THE BLAST RADIUS! 💥

At 127M downloads a week, this isn't a bug — it's a weaponized breach with a huge blast radius. 🦈 The attacker flooded the Keyv/Cacheable ecosystem with 2,000+ malicious versions, including keyv@6.0.0, mirroring the Shai-Hulud worm's automation. 🔍

This is how projects get gutted from the inside: credential theft, CI/CD key leaks, remote payloads, lateral movement through dev environments. Every downstream app touching this library is exposed. 📊

If you hold keys or run build pipelines on Node.js, treat your dependencies as compromised until audited. Rotate credentials and inspect lock files now. ⚠️ 💬 Is your project's dependency tree clean, or are you one package away from a nightmare? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #KEYV #SupplyChainAttack #CryptoSecurity #CyberAlert #NPM

🔍 🛡️
⚠️ Malware attack targets Vite via malicious npm packages Cybersecurity researchers have discovered seven malicious npm packages targeting the Vite frontend tooling environment in a software supply chain attack. These packages use Blockchain C2 technology to deliver RAT malware, highlighting the growing risks in the software development ecosystem. ━━━━━━━━━━━━━━ 📊 Impact: 📈 High 🏷️ OTHER #Cybersecurity #SupplyChainAttack #npm #Vite #Malware 🔗 Source: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
⚠️ Malware attack targets Vite via malicious npm packages

Cybersecurity researchers have discovered seven malicious npm packages targeting the Vite frontend tooling environment in a software supply chain attack. These packages use Blockchain C2 technology to deliver RAT malware, highlighting the growing risks in the software development ecosystem.

━━━━━━━━━━━━━━
📊 Impact: 📈 High
🏷️ OTHER

#Cybersecurity #SupplyChainAttack #npm #Vite #Malware

🔗 Source: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
🚨 Security alert: Hackers attempted to backdoor an Injective npm package to steal wallet keys. Supply-chain attacks are now targeting the crypto developer stack directly. According to security firm Socket, malicious code was injected into an npm package tied to Injective's wallet workflows — designed to silently siphon private keys and credentials from developers and the apps they build. Why it matters: • npm packages sit at the core of most Web3 front-ends and tooling • A single compromised dependency can drain countless user wallets • The incident hits Injective, a Cosmos-based L1 popular for DeFi and on-chain trading Socket researchers warned the risk is especially severe for apps that handle Injective wallet connections, where a tainted package could exfiltrate keys at the moment users sign in. The good news: the package was flagged before widespread adoption. But it's a stark reminder that "just npm install" is no longer safe in crypto. Teams should pin dependencies, audit lockfiles, and use scanner tools to catch suspicious post-install scripts. As more value moves on-chain, the attack surface shifts to the code itself. Stay paranoid, devs. 🔐 #Injective #CryptoSecurity #DeFi #Web3 #npm
🚨 Security alert: Hackers attempted to backdoor an Injective npm package to steal wallet keys.

Supply-chain attacks are now targeting the crypto developer stack directly. According to security firm Socket, malicious code was injected into an npm package tied to Injective's wallet workflows — designed to silently siphon private keys and credentials from developers and the apps they build.

Why it matters:
• npm packages sit at the core of most Web3 front-ends and tooling
• A single compromised dependency can drain countless user wallets
• The incident hits Injective, a Cosmos-based L1 popular for DeFi and on-chain trading

Socket researchers warned the risk is especially severe for apps that handle Injective wallet connections, where a tainted package could exfiltrate keys at the moment users sign in.

The good news: the package was flagged before widespread adoption. But it's a stark reminder that "just npm install" is no longer safe in crypto. Teams should pin dependencies, audit lockfiles, and use scanner tools to catch suspicious post-install scripts.

As more value moves on-chain, the attack surface shifts to the code itself. Stay paranoid, devs. 🔐

#Injective #CryptoSecurity #DeFi #Web3 #npm
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number