BTC $63,815.03 -2.27%
ETH $1,892.58 -3.12%
BNB $567.11 -1.29%
XRP $1.06 -3.98%
SOL $74.22 -3.14%
TRX $0.3250 -2.04%
DOGE $0.0704 -3.66%
ADA $0.1555 -5.94%
BCH $212.05 -1.96%
LINK $8.40 -4.46%
HYPE $56.28 -5.65%
AAVE $97.90 -2.40%
SUI $0.6817 -5.60%
XLM $0.1724 -5.46%
ZEC $477.15 -5.35%
BTC $63,815.03 -2.27%
ETH $1,892.58 -3.12%
BNB $567.11 -1.29%
XRP $1.06 -3.98%
SOL $74.22 -3.14%
TRX $0.3250 -2.04%
DOGE $0.0704 -3.66%
ADA $0.1555 -5.94%
BCH $212.05 -1.96%
LINK $8.40 -4.46%
HYPE $56.28 -5.65%
AAVE $97.90 -2.40%
SUI $0.6817 -5.60%
XLM $0.1724 -5.46%
ZEC $477.15 -5.35%

fog

All
Article
Flash

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Slow Fog: TRON users should be vigilant against phishing activities involving counterfeit TronLink Chrome extensions

SlowMist has issued a security warning stating that a high-risk phishing activity targeting TRON wallet users has been discovered. Attackers created a fake Chrome extension for the TronLink wallet, using Unicode bidirectional control characters and Cyrillic homographs to disguise the brand name. After installation, the extension loads a complete phishing page through a remote iframe, forming a "shell-core separation" credential theft chain.The malicious extension name uses homographs for disguise, and its Chrome Store page inherits the high user count and positive reviews of the real extension, lowering the review threshold. There is very little local code, only loading remote pages, making static analysis nearly impossible to detect malicious behavior. The remote phishing page perfectly replicates the official TronLink web wallet interface, stealing mnemonic phrases, private keys, Keystore files, and passwords, and relaying them in real-time via a Telegram Bot.Built-in anti-analysis features disable right-click, developer tools, drag-and-drop, and printing, and redirect based on the geographic and language settings of Russian users to evade detection. SlowMist recommends immediately uninstalling suspicious extensions, clearing local storage, checking for abnormal traffic, and if credentials have been entered, creating a new wallet and transferring assets immediately.
app_icon
ChainCatcher Building the Web3 world with innovations.