Open-Source Registry Polluted by Automated Token Farming Supply Chain Attack
An unprecedented supply chain attack polluted the npm registry with 150,000 malicious packages to exploit a token reward system, demonstrating critical open-source risk.
Lending Protocol Drained via Oracle Price Feed Manipulation on Base
Critical oracle failure on Base allowed asset mispricing, enabling immediate, under-collateralized fund extraction from the lending pool.
NPM Debug Package Compromised via Phishing, Redirecting Crypto Transactions
A compromised NPM package, widely integrated into browser-based applications, enabled malicious redirection of user cryptocurrency transactions.
