#比特币与黄金战争 Recently, the security community has circulated some concerning news. The Chief Information Security Officer of SlowMist team, 23pds, issued a warning on the platform — a new version of attack methods targeting the NPM supply chain, codenamed Shai-Hulud 3.0.



This is not the first time this issue has appeared. Previously, the Trust Wallet API key leak incident now appears to be very likely the work of Shai-Hulud 2.0. Supply chain attacks, if not防御, can have very serious consequences — especially for crypto projects and trading platforms.

So this warning is very targeted: all project teams and platforms need to immediately review their protective measures. As a hub of the development ecosystem, once the NPM layer is compromised, the impact can be very broad. Web3 security is no small matter; every vulnerability can escalate into a large-scale risk. It’s time to take these threats seriously.
BTC-0.23%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
0/400
ser_ngmivip
· 10h ago
Damn, another 3.0 version is out. These people are really idle, insisting on making things so complicated. The supply chain is really just about not pretending to be secure; I want to know which project dares to claim it's 100% safe. If the NPM line gets compromised, we're all doomed. Quickly check everything, everyone.
View OriginalReply0
ApeWithNoFearvip
· 10h ago
Damn, a new version is out again? This time I really need to check the dependencies thoroughly. If NPM gets compromised, the entire ecosystem will be doomed. I’m not wrong, am I? Trust Wallet was already quite outrageous last time, and now it’s happening again. How many projects need to be checked? It feels like my small contracts are getting nervous. Who can guarantee they haven’t been contaminated? Wait, what exactly does the 23pds warning mean? Just giving a code name sounds a bit vague. I really don’t want to be the next project to get hacked; I must take it seriously. Damn, Web3 security is always the biggest devil, more terrifying than market volatility.
View OriginalReply0
LeekCuttervip
· 10h ago
Here comes another new version, how long do we have to wait to prevent it forever? --- Trust Wallet didn't respond last time, and now 3.0 is out? That's incredible. --- If the NPM line gets stuck, the entire ecosystem will suffer, everyone needs to check themselves quickly. --- Every day there are new vulnerabilities and attacks, that's how exciting our industry is. --- Web3 security really never has a quiet moment; it's impossible to guard against everything. --- Chained security's warning this time should be taken seriously; don't regret it after being hacked. --- When will it finally settle down? One supply chain incident after another is so annoying. --- API keys can be leaked, which shows that security protection really needs to be upgraded.
View OriginalReply0
LightningLadyvip
· 10h ago
Shai-Hulud again? SlowMist's warning this time really cannot be ignored. Once the NPM chain is compromised, the consequences are unimaginable. Trust Wallet still has lingering fears from that incident. If the supply chain isn't well protected, it could really revert to the pre-Internet era overnight. Major project teams, hurry up and conduct self-inspections. Don't regret it only after something happens. Hackers nowadays have more tricks than we can imagine. It's getting intense. Web3 security is truly no small matter. A single vulnerability can be a fuse.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)