MikeTrendsTrends right now

search

SubQuery

Trends

  1. 1
    SubQuery's subql/common package compromised with credential-stealing code●Subql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repoYhnWarTerrorism107 h ago

    Version 5.8.3 of the subql/common npm package, maintained under the popular SubQuery repository, has been compromised with a malicious postinstall script that steals credentials. The issue was reported on GitHub and is drawing attention as the latest in a string of supply-chain attacks targeting widely used open-source packages, prompting warnings for developers to pin versions and audit their dependencies.

Repos