Open-Source Registry Polluted by Automated Token Farming Supply Chain Attack
An unprecedented supply chain attack polluted the npm registry with 150,000 malicious packages to exploit a token reward system, demonstrating critical open-source risk.
Developers Targeted by Supply Chain Attack Using Ethereum Smart Contracts
A sophisticated supply chain compromise leverages malicious npm packages and deceptive GitHub repositories, utilizing Ethereum smart contracts to covertly deliver malware payloads.
Malicious Rust Crates Hijack Developer Keys for Solana and Ethereum Wallets
A sophisticated supply chain attack, leveraging typosquatting in Rust's package registry, compromises developer environments to exfiltrate critical blockchain private keys.
Npm Supply Chain Compromise Redirects Cryptocurrency Transactions
A compromised developer account facilitated the injection of malicious code into widely used npm packages, enabling the silent redirection of cryptocurrency during transactions.
