1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
🚨 A brand-squatting npm package impersonating TanStack shipped malicious versions that exfiltrate environment variables from developers’ machines during install.
We spoke to @tannerlinsley, creator of @tan_stack, who confirmed that the maintainer of the unscoped tanstack package is not associated with TanStack or the official @tanstack/* projects in any way. The package is unrelated to the project's official CLI, and represents an ongoing brandjacking issue.
He also said TanStack has filed legal documents related to a pending trademark infringement claim against the maintainer, that the maintainer previously demanded $10,000 from him, and that TanStack has repeatedly tried, unsuccessfully, to get @npmjs to address the situation.
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
Announcing Built with Opus 4.6: a Claude Code virtual hackathon.
Join the Claude Code team for a week of building. Winners will be hand-selected to win $100K in Claude API credits.
Apply here: https://t.co/SkEg8Py1l2
𝗧𝗵𝗲 𝗧𝗼𝗿𝗻𝗮𝗱𝗼 𝗟𝗮𝘂𝗻𝗰𝗵𝗲𝗿 𝗔𝗽𝗽 𝗶𝘀 𝗵𝗲𝗿𝗲! 📱
Launch and trade new @blast tokens directly from the app. Visit https://t.co/lsRoqzo6TM and add it to your home screen!
Click on Trade with Tornado Bot to open your Telegram and its associated wallet.
𝗧𝗵𝗲 𝗧𝗼𝗿𝗻𝗮𝗱𝗼 𝗟𝗮𝘂𝗻𝗰𝗵𝗲𝗿 𝗔𝗽𝗽 𝗶𝘀 𝗵𝗲𝗿𝗲! 📱
Launch and trade new @blast tokens directly from the app. Visit https://t.co/lsRoqzo6TM and add it to your home screen!
Click on Trade with Tornado Bot to open your Telegram and its associated wallet.
Tornado Token is Live! 🪂
$TRDNO is finally live on @ThrusterFi with a first airdrop!
CA: 0x9E92C0B2b84DDac571BdE330C4b44096A7c99909
Read the announcement to learn everything about this new token 👇
Introducing Abstract, the blockchain for consumer crypto.
Through @IglooInc; @foundersfund, @fenbushi, @1kxnetwork and others will contribute towards bringing the next generation of crypto users, onchain.
Learn more and how to participate below:
$TRNDO is around the corner 🪙
The token will be live starting this Wednesday on @ThrusterFi!
Tornado and its community have been at the heart of the @blast ecosystem since its inception.
In just 5 months, Tornado has introduced two products:
▰ The leading Telegram Trading Bot on the chain with over $120M in trading volume and 35,000 unique users.
▰ A new Token Launcher, with several tokens already reaching the top trending spots on the chain. Integrated with @ThrusterFi and @BlasterSwap.
$TRNDO token aims to reward our most loyal users who have supported the project since day one with a series of airdrops and to allow everyone to take part in the development of the Blast ecosystem while benefiting from the projects driven by Tornado.
This first season has laid a solid foundation and firmly established Tornado within the ecosystem. This token is the means to start season two by aligning the interests of the team with those of the community!
More information will be announced in the coming days!
The Blast Phase 2 guide for Dapps is now live. Read the guide to understand how Phase 2 works in terms of Points, Gold, Big Bang, and more.
Don't want to read or have more questions? Join our Builder AMA in Discord July 9 at 12PM ET
https://t.co/v0ILpFFpbL