Register and share your invite link to earn from video plays and referrals.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
Joined April 2018
408 Following    88.8K Followers
🚨 SlowMist TI Alert 🚨 The Mini Shai-Hulud, Miasma, and Hades malware family, now expanding beyond npm into the Go module ecosystem. Affected Go modules: is a Cosmos SDK-based Layer 1 blockchain project for decentralized trust and verifiable registry infrastructure. The compromised repository contains obfuscated payloads under .claude/, execution logic in .claude/setup.mjs and .vscode/setup.mjs, and VS Code/AI assistant workflow hooks that may trigger payload execution when the repository is opened. This is not a traditional Go build-time compromise. The risk lies in source-repository and developer-environment abuse through IDE automation, AI hooks, and hidden workspace configuration. Security teams should avoid opening untrusted repositories with IDE automation enabled, audit .claude and .vscode files, and rotate any potentially exposed developer, cloud, repository, and CI/CD credentials. Special thanks to @SocketSecurity for the excellent discovery. As always, stay vigilant!
Show more