🚨 CRITICAL SUPPLY CHAIN ATTACK LIVE RIGHT NOW


@feross just dropped this: axios (100M+ weekly downloads) latest versions 1.14.1 and 0.30.4 were compromised.
The attacker hijacked the maintainer’s npm account and slipped in plain-crypto-js@4.2.1, a full RAT dropper that:
• Runs on postinstall (no import needed)
• Deobfuscates & executes shell commands
• Drops platform-specific malware (macOS, Windows, Linux)
• Self-destructs to hide tracks
Popular crypto platforms and wallets that rely on axios (directly or indirectly) include:
• MetaMask
• Trust Wallet
• Coinbase Wallet
• Uniswap
• OpenSea
• Phantom
Crypto Jargon alpha:
If you run ANY Node.js crypto tooling (MEV bots, trading scripts, on-chain indexers, wallet connectors, etc.) you are exposed right now.
Pin axios to 1.14.0 or 0.30.3 immediately. Audit your lockfiles. Assume compromise if you installed in the last 12 hours.
The irony of the package name “plain-crypto-js” writing malware… chef’s kiss 😭
You already running Socket Security or pinned your deps? Or still “npm install latest” gang?
UNI-0,62%
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin