Scan to download
BTC $69,505.39 -4.62%
ETH $1,970.15 -0.71%
BNB $679.39 -1.62%
XRP $1.26 -3.56%
SOL $79.23 -2.28%
TRX $0.3404 -3.11%
DOGE $0.0987 -1.08%
ADA $0.2230 -3.65%
BCH $284.62 -1.41%
LINK $8.80 -2.34%
HYPE $71.56 -1.91%
AAVE $77.45 -4.71%
SUI $0.8425 -4.19%
XLM $0.2309 -8.70%
ZEC $551.79 +0.57%
BTC $69,505.39 -4.62%
ETH $1,970.15 -0.71%
BNB $679.39 -1.62%
XRP $1.26 -3.56%
SOL $79.23 -2.28%
TRX $0.3404 -3.11%
DOGE $0.0987 -1.08%
ADA $0.2230 -3.65%
BCH $284.62 -1.41%
LINK $8.80 -2.34%
HYPE $71.56 -1.91%
AAVE $77.45 -4.71%
SUI $0.8425 -4.19%
XLM $0.2309 -8.70%
ZEC $551.79 +0.57%

over

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

CME officially launched 24/7 cryptocurrency futures and options trading, with over 50 million dollars in transactions on the first weekend

According to official news, the world's largest derivatives exchange group, CME Group, announced the official launch of a 7×24 hour continuous trading mechanism for cryptocurrency futures and options products. The new trading session started on May 29, marking the first time that the traditional regulated derivatives market has fully aligned with the "around-the-clock trading" model for crypto assets.According to data disclosed by CME, over 7,200 cryptocurrency futures and options contracts were traded during the first weekend after the service went live, corresponding to a nominal trading volume of approximately $50 million, demonstrating the immediate demand for weekend liquidity from institutional and retail investors. Tim McCourt, CME's Global Head of Equity, FX, and Alternative Products, stated that cryptocurrency assets themselves operate on a 7×24 hour trading basis, and the launch of the around-the-clock trading mechanism by CME aims to bridge the time gap between the traditional regulated market and the crypto spot market, enabling continuous price discovery and risk management.At the same time, CME's newly launched Bitcoin Volatility Futures also opened for 7×24 hour trading. This product allows investors to trade the implied volatility of Bitcoin for the next 30 days directly, without bearing the risk of Bitcoin price fluctuations. Market participants believe this move indicates that the traditional financial system is further aligning with the crypto market. Following spot ETFs, tokenized assets, and stablecoins, the regulated crypto derivatives market is also beginning to evolve towards the same around-the-clock trading model as the spot market, which helps enhance institutional participation and improve weekend market liquidity.
app_icon
ChainCatcher Building the Web3 world with innovations.