11-25
Supply-Chain Attack Compromises 490+ NPM Packages With 132 Million Monthly Downloads
A supply-chain breach has infected over 490 npm packages recording 132 million monthly downloads, targeting libraries linked to Ethereum Name Service, Zapier, and other cryptocurrency platforms, according to Aikido Security. The malware steals developer credentials and GitHub tokens during installation. If stolen credentials provide access to code repositories, attackers can breach additional accounts and distribute more compromised packages, enabling autonomous spread.
Вибрані
11-25
11-24
Shai Hulud Malware Infects Over 400 NPM Packages Including ENS Libraries
A supply chain attack on the NPM ecosystem has infected more than 400 JavaScript packages, including at least 10 crypto libraries tied to Ethereum Name Service, according to Aikido Security. The malware collects credentials from compromised environments and has spread to over 25,000 repositories. Aikido Security disclosed the breach on Monday after detecting unusual activity across the JavaScript package registry.
Вибрані
ENS
ENS+10.23%
11-24
11-24
North Korean Operatives May Account for 20% of Crypto Company Hires, Security Expert Says
North Korean operatives could be working at up to 20% of cryptocurrency companies, according to Pablo Sabbatella, founder of Web3 audit firm Opsek and Security Alliance member. Between 30% and 40% of job applications at crypto firms may come from such operatives, who use stolen identities and freelance platforms to gain employment. The threat extends beyond financial theft to unauthorized access to critical infrastructure supporting major platforms.
11-24
11-24
Hong Kong to Grant First Stablecoin Licenses in Early 2026 Under Strict Reserve Rules
Hong Kong's monetary authority has received approximately 80 applications for stablecoin issuer licenses, with only a limited number expected to gain approval in early 2026. The jurisdiction has become the first to mandate that stablecoin reserves consist exclusively of High Quality Liquid Assets. The framework follows several digital asset scandals and establishes centralized oversight under the Hong Kong Monetary Authority.
11-24
11-24
Vibe coding and no-code tools reshape web3 application development
Vibe coding enables users to build and deploy applications through natural language commands rather than traditional coding. Eric Chen, cofounder of Injective, said the protocol's iBuild platform allows developers and non-developers to create functional web3 applications within minutes using AI-powered tools. Industry surveys indicate approximately 75% of developers at early-stage startups now incorporate vibe coding into their workflows, with more than half reporting delivery velocity increases of at least 30%.
11-24