MikeTrendsTrends right now

Yhn WarTerrorism first seen 1 d ago, last 3 h ago, peak #8

SubQuery's subql/common package compromised with credential-stealing code

Original: Subql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo

Version 5.8.3 of the subql/common npm package, maintained under the popular SubQuery repository, has been compromised with a malicious postinstall script that steals credentials. The issue was reported on GitHub and is drawing attention as the latest in a string of supply-chain attacks targeting widely used open-source packages, prompting warnings for developers to pin versions and audit their dependencies.

Why now: Developers are alarmed by another supply-chain attack hitting a high-star open-source project, raising fresh concerns about npm package security.

SubQuerysubql/commonnpmGitHub

Open on hn →

Rank over time, top of the chart is #1. 7 snapshots from 22 h ago to 3 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1519839