search
SubQuery
Trends
- 1SubQuery npm package compromised with credential-stealing code●Subql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo
Version 5.8.3 of the Subql/common package, part of the widely used SubQuery project with around 18,000 GitHub stars, has been compromised and contains a credential-stealing script that runs automatically on install via its postinstall hook. The issue was flagged publicly on the project's GitHub repository, and developers are being warned to avoid installing the affected version while the supply-chain attack is investigated.
Repos
- subquery/subql SubQuery is an Open, Flexible, Fast and Universal data indexing framework for web3. Our mission is to help developers cr