Security Advisory: Another well-known developer's NPM account has been compromised, injecting wallet-stealing malware
BlockBeats News, September 9th. According to Socket monitoring, the ongoing NPM supply chain attack has spread from the well-known developer Qix to another highly prominent maintainer. The NPM account duckdb_admin, responsible for the DuckDB-related package, has been compromised, and multiple malicious versions have been published. The injected code is the same wallet-stealing malware used when Qix's account was compromised, strongly indicating that both are part of the same attack campaign.
Previously reported, Ledger's CTO stated that in the event of a large-scale supply chain attack, the entire JavaScript ecosystem could be at risk. However, the NPM attackers were not successful, and there were almost no victims.
Também poderá gostar de
Em alta
Últimas Crypto News
Arthur Hayes: Liquidez do mercado mostra ligeira melhoria, mas BTC ainda enfrenta a possibilidade de retest $80,000
Deutsche Bank 2026 Outlook: Objetivo do S&P 500 para o fim do ano é de 8000 pontos
Um homem em São Francisco, EUA, invadiu uma casa e roubou cerca de US $ 11 milhões em criptomoedas.
O New Jersey Pension Fund aumenta a participação da MicroStrategy para US$ 16 milhões
Uma baleia comprou os fundos restantes para HYPE spot, com o tamanho atual da posição em torno de US $ 15,5 milhões.
Apoio ao cliente:@weikecs
Cooperação empresarial:@weikecs
Trading quant. e criação de mercados:[email protected]
Serviços VIP:[email protected]