登録して招待リンクを共有すると、動画再生報酬と紹介報酬を獲得できます。

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
参加 April 2018
408 フォロー中    88.8K ファン
🚨 SlowMist TI Alert 🚨 The Mini Shai-Hulud, Miasma, and Hades malware family, now expanding beyond npm into the Go module ecosystem. Affected Go modules: is a Cosmos SDK-based Layer 1 blockchain project for decentralized trust and verifiable registry infrastructure. The compromised repository contains obfuscated payloads under .claude/, execution logic in .claude/setup.mjs and .vscode/setup.mjs, and VS Code/AI assistant workflow hooks that may trigger payload execution when the repository is opened. This is not a traditional Go build-time compromise. The risk lies in source-repository and developer-environment abuse through IDE automation, AI hooks, and hidden workspace configuration. Security teams should avoid opening untrusted repositories with IDE automation enabled, audit .claude and .vscode files, and rotate any potentially exposed developer, cloud, repository, and CI/CD credentials. Special thanks to @SocketSecurity for the excellent discovery. As always, stay vigilant!
もっと見る