Slow fog warning, over 140 Mastra npm packages suffered supply chain attacks
Slow Fog stated that over 140 Mastra-related npm packages were subjected to a supply chain attack, with the affected versions introducing the malicious dependency easy-day-js@1.11.22, triggering code execution controlled by the attacker during the installation phase.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Anthropic Launches Free Platform Claude Academy

Ukrainians Abroad Can Obtain an Electronic Taxpayer Card with QR Code

Lingguang App Launches One-Click Deployment Feature Supporting Multiple AI Applications

Qubic GitHub Account Compromised, Wallet Users Must Migrate Immediately

Google Launches AlphaEvolve AI Code Optimization Agent

The Hang Seng Hong Kong-Mainland Technology Index will include SpaceX

Grayscale plans to launch a Hyperliquid staking ETF with management fees lower than Bitwise and 21Shares

Vitalik updates on CROPS AI progress: proposes combining private remote LLM calls with Ethereum private RPC reads

Argentina's anti-gambling bill for the first time includes cryptocurrency exchanges under regulation, with violations punishable by 2 to 4 years in prison

UK AI agency security and governance platform Geordie AI completes $30 million Series A funding, led by Balderton Capital

The smart DeFi assistant Otomato has completed a $2 million financing round, led by Improbable

DeFi has reached its most dangerous moment: the real vulnerabilities are not in the code

Alipay has launched AI wallet products and Token Pay, and its AI payment now supports 95% of general intelligent agent frameworks

GitHub is suspected to have been hacked and is investigating an incident of unauthorized access to its internal code repository

Zhao Changpeng reminds about the GitHub security incident, API Keys in private repositories should be reviewed and replaced immediately

Morning News | VanEck and Grayscale submitted BNB ETF amendments on the same day; BlackRock discusses investing billions of dollars in SpaceX's IPO; Michael Saylor releases Bitcoin Tracker information again

T Rowe submitted the third revised document for the Active Crypto ETF

The Smarter Web Company increased its holdings by 44 BTC, with a total holding of 2750 BTC

Slow Fog: HexagonalRodent is targeting Web3 developers with attacks

Warning, version 1.14.1 of the npm core package axios is experiencing an active supply chain attack

Apifox desktop client suffers from a supply chain attack, malicious code can steal credentials and execute commands remotely

WeChat launches official lobster plugin

Holdstation suffered a hacker attack, losing 462,000 USDT. Services have been suspended and a full compensation has been promised

Backpack announces token code "BP" and contract address

The China Academy of Information and Communications Technology collaborates with universities to discover and fix the high-risk command injection vulnerability in OpenClaw

The listed company UTime plans to acquire the Web3 data platform "Fei Xiao Hao" for 80 million USD

Slow Fog: ClawHub developers please be aware of phishing and credential leakage risks

Grayscale Avalanche Staking ETF will begin trading tomorrow

Nanjing Qixia District and Jiangning District issued a "Crayfish Farming" policy



