Scan to download
BTC $66,907.00 -3.80%
ETH $1,876.74 -4.78%
BNB $643.91 -5.38%
XRP $1.24 -1.62%
SOL $74.89 -5.68%
TRX $0.3328 -2.27%
DOGE $0.0937 -5.17%
ADA $0.2161 -3.31%
BCH $249.94 -12.26%
LINK $8.51 -3.39%
HYPE $72.15 +1.30%
AAVE $76.00 -2.19%
SUI $0.8334 -1.52%
XLM $0.2291 -0.35%
ZEC $618.54 +10.43%
BTC $66,907.00 -3.80%
ETH $1,876.74 -4.78%
BNB $643.91 -5.38%
XRP $1.24 -1.62%
SOL $74.89 -5.68%
TRX $0.3328 -2.27%
DOGE $0.0937 -5.17%
ADA $0.2161 -3.31%
BCH $249.94 -12.26%
LINK $8.51 -3.39%
HYPE $72.15 +1.30%
AAVE $76.00 -2.19%
SUI $0.8334 -1.52%
XLM $0.2291 -0.35%
ZEC $618.54 +10.43%

cloud

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Tencent Cloud Industry Architect Alan Nie: The dual engines of Cloud + AI drive Web3 to break through the bottlenecks of infrastructure and R&D efficiency

At the "Crypto 2026: From Cryptocurrency to Smart Economy" themed forum held in Hong Kong, Tencent Cloud's industry architect Alan Nie delivered a keynote speech titled "Cloud + AI Dual Engine: Tencent Cloud Empowers New Growth in Web3."Alan Nie pointed out that Web3 enterprises face three major bottlenecks in global infrastructure, R&D efficiency, and business intelligence. Tencent Cloud deeply integrates the "Cloud + AI" dual engine to provide low-latency infrastructure covering the globe. Among them, the Singapore data center is the only cloud provider in the world that offers four availability zones, and the self-developed TDSQL-C database can achieve elastic scaling in seconds, with Redis single-node performance reaching over 300,000.In terms of AI empowerment, Tencent Cloud launched CodeBuddy (AI Pair Programmer) and WorkBuddy (Personal AI Assistant), which can automatically generate code, batch process office documents, organize meeting minutes, and support multi-agent parallel execution of complex tasks. In financial scenarios, the automation research report reproduction cycle has been shortened from three days to half a day; in on-chain data analysis scenarios, storage costs have been reduced to one-tenth of the original, with query responses reaching millisecond levels.Alan Nie stated that Tencent Cloud is committed to using the "Cloud + AI" dual engine to help Web3 enterprises build the next generation of smart economic infrastructure.
app_icon
ChainCatcher Building the Web3 world with innovations.