MikeTrendsTrends right now

Yhn WarTerrorism first seen 3 d ago, last 1 h ago, peak #6

SubQuery npm package compromised with postinstall malware

Original: Subql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo

Version 5.8.3 of the subql/common package, part of the widely used SubQuery project with around 18,000 GitHub stars, has been compromised and ships a credential-stealing script in its postinstall hook. The issue was reported publicly on the project's GitHub tracker, warning developers who installed the affected version to treat their secrets as exposed and rotate credentials immediately.

Why now: Developers are urgently checking whether they installed the malicious version and rotating credentials, as supply-chain attacks on popular npm packages spread quickly through CI and local environments.

SubQuerysubql/commonnpmGitHub

Open on hn →

Rank over time, top of the chart is #1. 39 snapshots from 3 d ago to 1 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1519839