Scan to download
BTC $69,677.72 -4.18%
ETH $1,976.27 -0.09%
BNB $680.54 -1.01%
XRP $1.26 -2.93%
SOL $79.43 -1.77%
TRX $0.3404 -3.16%
DOGE $0.0990 -0.48%
ADA $0.2236 -3.14%
BCH $285.33 -1.13%
LINK $8.82 -1.83%
HYPE $71.31 -0.96%
AAVE $77.68 -3.93%
SUI $0.8448 -3.44%
XLM $0.2287 -9.30%
ZEC $556.76 +1.79%
BTC $69,677.72 -4.18%
ETH $1,976.27 -0.09%
BNB $680.54 -1.01%
XRP $1.26 -2.93%
SOL $79.43 -1.77%
TRX $0.3404 -3.16%
DOGE $0.0990 -0.48%
ADA $0.2236 -3.14%
BCH $285.33 -1.13%
LINK $8.82 -1.83%
HYPE $71.31 -0.96%
AAVE $77.68 -3.93%
SUI $0.8448 -3.44%
XLM $0.2287 -9.30%
ZEC $556.76 +1.79%

w

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Solana officially stated that it will vigorously promote the construction of fully on-chain perpetual contracts, aiming to become the world's strongest on-chain financial derivatives infrastructure

Solana's official announcement "Building Fully On-Chain Perpetual Contracts on Solana" aims to vigorously promote the ecological construction of fully on-chain perpetual contracts (Perps) in the future, with the goal of making Solana the world's strongest on-chain financial derivatives infrastructure. Currently, the trading volume of crypto derivatives is mainly concentrated on centralized trading platforms or hybrid models that rely on off-chain matching engines, which Solana believes is a transitional phase. It hopes to make a truly fully on-chain derivatives market a reality through the characteristics of high-performance blockchain—where all processes such as order submission, price updates, matching, and clearing are completed on-chain, while maintaining institutional-level speed and low costs.The Solana Foundation will provide funding, technical support, and resource allocation, focusing on supporting projects that meet the following criteria: fully on-chain execution, price discovery based on real bilateral liquidity (rather than purely pool pricing), Solana priority with revenue flowing back on-chain, teams with derivatives experience, and core code being open source. It also welcomes the co-construction of surrounding infrastructure such as front ends, aggregators, vaults, and market-making tools.
app_icon
ChainCatcher Building the Web3 world with innovations.