🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
Imagine CEO of a security firm showcasing 6 of his "best" auditors running an 11-week audit and missing 11 highs, 17 meds, then running it as a success story for their automated scanning tool.
All these finds are superhuman? Prove it.
Humans didn't have time to find them? Then you heavily underscoped required effort.
Doesn't strike as a confidence booster to clients paying deep 6-figures for an audit and expecting reasonable coverage.
At TrustSec we'd rather lose the deal than ship a report we can't defend, but maybe that's just us.
Introducing Claude Code Security, now in limited research preview.
It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss.
Learn more: https://t.co/n4SZ9EIklG
Introducing EVMbench—a new benchmark that measures how well AI agents can detect, exploit, and patch high-severity smart contract vulnerabilities. https://t.co/op5zufgAGH
Prompt engineering is dead.
Anthropic just published their internal playbook on what actually matters: XML-structured prompting.
Only 2% of users know this exists.
Here's what changed:
One of the best articles I have EVER read.😮
A former hacker, currently a CEO explaining:
- How Money Works, Startups and VCs
- The Birth of a Shitcoin and more
"A hacker is someone who understands how the world works."
https://t.co/C2vuCLJrjc