Yhn WarTerrorism first seen 2 d ago, last 22 min ago, peak #8
SubQuery npm package compromised with credential-stealing code
Original: Subql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo
Version 5.8.3 of the Subql/common package, part of the widely used SubQuery project with around 18,000 GitHub stars, has been compromised and contains a credential-stealing script that runs automatically on install via its postinstall hook. The issue was flagged publicly on the project's GitHub repository, and developers are being warned to avoid installing the affected version while the supply-chain attack is investigated.
Why now: A popular open-source dependency was found to ship malware, raising immediate supply-chain security concerns for developers.
Rank over time, top of the chart is #1. 9 snapshots from 11 h ago to 22 min ago.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1519839