BTC $79,395.97 -0.72%
ETH $2,488.78 -0.41%
BNB $743.54 -1.93%
XRP $1.40 -1.32%
SOL $105.02 -1.54%
TRX $0.3368 +0.76%
DOGE $0.0895 -0.44%
ADA $0.2185 -0.27%
BCH $256.00 -1.70%
LINK $13.30 +8.45%
HYPE $87.53 -0.17%
AAVE $133.58 -0.77%
SUI $0.8095 +1.46%
XLM $0.1910 +2.58%
ZEC $1,192.52 +0.67%
BTC $79,395.97 -0.72%
ETH $2,488.78 -0.41%
BNB $743.54 -1.93%
XRP $1.40 -1.32%
SOL $105.02 -1.54%
TRX $0.3368 +0.76%
DOGE $0.0895 -0.44%
ADA $0.2185 -0.27%
BCH $256.00 -1.70%
LINK $13.30 +8.45%
HYPE $87.53 -0.17%
AAVE $133.58 -0.77%
SUI $0.8095 +1.46%
XLM $0.1910 +2.58%
ZEC $1,192.52 +0.67%

slowmist

Все
Статьи
Новости

Обнаружены новые виды мошенничества с наймом для работников Web3, вредоносное ПО маскируется под инструменты для интервью с использованием ИИ

Сообщение ChainCatcher, SlowMist опубликовал информацию о недавно обнаруженной мошеннической деятельности, связанной с наймом для специалистов Web3. Злоумышленники выдают себя за рекрутеров, подталкивая жертв установить программное обеспечение для AI-видеоконференций под названием "Relay", которое на самом деле является вредоносной программой для кражи информации.Этот вредоносный софт нацелен как на пользователей macOS, так и на пользователей Windows, и может похищать учетные данные браузера, данные криптовалютных кошельков, данные Keychain, сессии Telegram и другую чувствительную информацию. SlowMist завершил анализ образцов и раскрыл способ работы этой цепочки атак. SlowMist напоминает, что при участии в онлайн-собеседованиях или процессах найма следует осторожно устанавливать незнакомое программное обеспечение, избегать запуска непроверенных приложений и обращать внимание на необычные запросы на установку или подсказки системного пароля.

OKX совместно с Elliptic, SlowMist и OttoSec опубликовали отчет по безопасности и управлению рисками Web3 за первую половину 2026 года

Сообщение ChainCatcher, согласно официальным данным, OKX совместно с Elliptic, SlowMist, OttoSec выпустила «Отчет о безопасности и управлении рисками Web3 за первую половину 2026 года». В отчете отмечается, что акцент атак Web3 постепенно смещается с кода смарт-контрактов на более сложные сценарии, такие как процессы подписи, пользовательские устройства, инфраструктура эксплуатации и AI Agent.Данные показывают, что за первую половину 2026 года система управления рисками OKX заблокировала более 5,7 миллиона высокорисковых транзакций, из которых около 2,41 миллиона транзакций были связаны с хакерами и кражами, около 1,48 миллиона транзакций были связаны с фишингом, и около 990 тысяч транзакций были связаны с мошенничеством. Библиотека меток разведывательной информации OKX Web3 в настоящее время содержит более 1 миллиарда меток, охватывающих более 420 цепочек, и интегрирует возможности проверки адресов, мониторинга транзакций и управления санкционными адресами в такие инфраструктуры, как DEX и Exchange OS.Кроме того, в области защиты пользователей OKX заблокировала более 7 миллионов попыток доступа к рискованным сайтам, провела более 200 тысяч проверок рисков устройств, идентифицировала более 60 тысяч высокорисковых приложений и заблокировала или выдала предупреждения по более чем 4 миллионам высокорисковых операций с подписями. В отчете также представлено проектирование «предварительного управления рисками» в таких сценариях, как Exchange OS, Outcomes, RWA и Agentic Wallet.

Безопасное предупреждение: 30 вредоносных npm пакетов маскируются под репозитории торговых роботов, целенаправленно крадут ключи разработчиков и мнемонические фразы

Сообщение ChainCatcher, SlowMist выпустила предупреждение о безопасности, обнаружив скоординированную злонамеренную атаку на цепочку поставок npm, в которой злоумышленники использовали поддельные репозитории торговых ботов и npm-пакеты на тему DeFi для распространения JavaScript-воришек информации, нацеленных на пользователей npm, разработчиков DeFi и пользователей торговых ботов.В этой атаке участвуют 30 злонамеренных npm-пакетов, среди которых stake-math@3.5.4 появляется в качестве заблокированной зависимости в репозитории donoaccestag/forex-mt5-trading-bot, который содержит около 2300 высоко однородных массово сгенерированных форков, большинство из которых сосредоточено на аккаунте poly-stocks, сигнал очень четкий. Злоумышленники могут украсть широкий спектр конфиденциальных данных, включая библиотеки криптокошельков, куки браузера и сохраненные пароли, историю просмотров, учетные данные разработчиков, историю команд Shell, библиотеки менеджеров паролей, приватные ключи, мнемонические фразы и API-токены, раскрытые в исходном коде.SlowMist рекомендует разработчикам немедленно удалить затронутые npm-пакеты, провести аудит package.json и package-lock.json, а также CI-логов на наличие любого из 30 злонамеренных пакетов; рассматривать системы, на которых выполнялась команда npm install, как потенциально скомпрометированные, сменить все раскрытые кошельки, приватные ключи, токены npm, облачные учетные данные, SSH-ключи и API-токены, а также восстановить затронутую среду из чистого образа.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Nano Labs, SlowMist, and Aquarius announced the establishment of the Fortress Foundation and launched its first initiative, the Fortress Initiative

ChainCatcher news, Nano Labs, SlowMist, and Aquarius announced the establishment of the Fortress Foundation and launched its first initiative—the Fortress Initiative. This is a framework for liquidity management security design and process audit standards, aimed at setting a new benchmark for security and transparency in the cryptocurrency liquidity management field. The initiative provides detailed security guidelines for liquidity management protocols and establishes practices for auditing liquidity management processes, supplemented by practical case studies to ensure operability.The core vision of the Fortress Initiative is to establish global standards for liquidity management security and process auditing, thereby building trust across the entire cryptocurrency ecosystem. Its mission is to provide cutting-edge security frameworks and rigorous audit standards, enabling organizations to effectively protect digital assets while optimizing liquidity management operations.The initiative follows a comprehensive one-year roadmap aimed at achieving a seamless transition from concept to full industry integration. The initial phase focuses on foundational development work, including defining concepts, establishing brand identity, assembling core contributors and partner organizations, and drafting frameworks through collaboration with key stakeholders. During this phase, the team developed risk assessment protocols, audit methodologies, and penetration testing plans, which were validated through pilot case studies. Subsequently, the launch phase will collect feedback and drive participation through formal releases, interactive panel discussions, live demonstrations, and community workshops at major industry events. The final phase will optimize and expand the framework based on early audit results, incorporate regulatory compliance measures, establish a trained network of auditors, and culminate in a security summit to showcase progress and plan future strategies.The Fortress team stated that in the early stages of the project, they will focus on inviting asset management protocols and ecosystem partners with BTC staking needs to participate in the construction.The initiative has received strong support from industry-leading organizations. Nano Labs (Nasdaq: NA) is a publicly listed company on Nasdaq and a leading chip design company in Asia, at the forefront of technological innovation and recognized as a major and steadfast holder of Bitcoin. SlowMist is a globally renowned blockchain security company with over a decade of professional experience, bringing unparalleled expertise to the field of cybersecurity. Aquarius is a research-driven asset management company managing over $600 million in assets, providing rich expertise in liquidity management and liquidity management strategies. Additionally, the Sei native lending protocol Takara Lend, supported by Sei Blockchain, joined as one of the first donating members, highlighting their commitment to collaboratively establish standards and processes that will shape the future of liquidity management security.The technical framework of the Fortress Initiative is equally robust, with security standards covering the entire liquidity management lifecycle—from pre-liquidity management assessments, continuous monitoring, to post-management issue response systems—integrating comprehensive testing, monitoring, coordination, and tracking systems comparable to ISO 9001 standards. This framework includes detailed smart contract code audits, comprehensively checking for issues such as permission vulnerabilities, security design, design logic, variable coverage, variable declarations and scopes, arithmetic accuracy, uninitialized storage pointers, and denial-of-service attacks. Additionally, the framework encompasses rigorous security awareness testing conducted through red team testing and phishing simulations, comprehensive multi-chain asset security monitoring, and thorough assessments of internal management processes, including recruitment, code deployment, incident response, and multi-signature wallet management.The Fortress Foundation is a non-profit organization dedicated to promoting blockchain security, with the goal of establishing standards for security and transparency in the liquidity management ecosystem.
Nano Labs, SlowMist, and Aquarius announced the establishment of the Fortress Foundation and launched its first initiative, the Fortress Initiative
app_icon
ChainCatcher Building the Web3 world with innovations.