MikeTrendsTrends right now

Yhn WarTerrorism first seen 1 d ago, last 1 h ago, peak #8

SubQuery's subql/common package compromised with credential-stealing script

Original: Subql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo

A malicious postinstall script was found in version 5.8.3 of the subql/common package in the SubQuery repository, which has around 18,000 stars on GitHub. The package is used by developers building with SubQuery, so anyone installing the compromised version could have credentials or secrets stolen automatically. A GitHub issue has been opened to flag and track the compromise, and developers are being warned to avoid 5.8.3.

Why now: A popular open-source dependency being hijacked puts many developers' credentials at risk, prompting urgent warnings across the community.

SubQuerysubql/commonGitHub

Open on hn →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1519839