๐Ÿšจ CRITICAL SUPPLY CHAIN ATTACK LIVE RIGHT NOW


@feross just dropped this: axios (100M+ weekly downloads) latest versions 1.14.1 and 0.30.4 were compromised.
The attacker hijacked the maintainerโ€™s npm account and slipped in plain-crypto-js@4.2.1, a full RAT dropper that:
โ€ข Runs on postinstall (no import needed)
โ€ข Deobfuscates & executes shell commands
โ€ข Drops platform-specific malware (macOS, Windows, Linux)
โ€ข Self-destructs to hide tracks
Popular crypto platforms and wallets that rely on axios (directly or indirectly) include:
โ€ข MetaMask
โ€ข Trust Wallet
โ€ข Coinbase Wallet
โ€ข Uniswap
โ€ข OpenSea
โ€ข Phantom
Crypto Jargon alpha:
If you run ANY Node.js crypto tooling (MEV bots, trading scripts, on-chain indexers, wallet connectors, etc.) you are exposed right now.
Pin axios to 1.14.0 or 0.30.3 immediately. Audit your lockfiles. Assume compromise if you installed in the last 12 hours.
The irony of the package name โ€œplain-crypto-jsโ€ writing malwareโ€ฆ chefโ€™s kiss ๐Ÿ˜ญ
You already running Socket Security or pinned your deps? Or still โ€œnpm install latestโ€ gang?
UNI4.79%
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments