This article is machine translated
Show original

The attacker is using the latest tools. The defender is not. 🚨 Axios, one of the most widely used programming libraries on npm (a package management system for JavaScript), has just been subjected to a supply chain attack. Version axios@1.14.1 was embedded with a strange package called plain-crypto-js@4.2.1, which did not exist before March 31st. Any project that updated axios on that day risked having malware installed without their knowledge. Haseeb Qureshi, one of the most reputable Web3 venture capitalists today, calls this a sign of a "hacking vibe" becoming a systemic problem. Attackers are focused, organized, and use the latest AI tools to find vulnerabilities. Defenders, on the other hand, are dispersed, often individual volunteer maintainers, lacking the resources to keep up.

Upside GM
@gm_upside
⚠️ Drift Protocol có vẻ đã bị hack rất nặng. Thiệt hại khoảng trên 270 triệu USD. Trớ trêu là theo Lookonchain thì hacker đang swap lượng tài sản bị hack thành USDC, rồi bridge từ Solana sang Ethereum để mua ETH. Hacker là fan của ETH đấy à? Hiện tại khoảng x.com/gm_upside/stat…
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments