MikeTrendsTrends right now

Yhn WarTerrorism first seen 2 d ago, last 26 min ago, peak #8

SubQuery npm package compromised in supply chain attack

Original: Subql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo

Version 5.8.3 of the subql/common npm package used by the open-source SubQuery project has been compromised, with a malicious postinstall script that steals data reportedly included. The issue was flagged in the project's GitHub repository, where maintainers and security researchers are urging users to avoid the affected version and audit their systems. The repo has roughly 18,000 stars, widening potential exposure among blockchain developers.

Why now: A fresh supply chain compromise of a widely used open-source package puts developers at immediate risk of credential theft.

SubQuerysubql/commonnpmGitHub

Open on hn →

Rank over time, top of the chart is #1. 2 snapshots from 1 h ago to 26 min ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1519839