Scan to download
BTC $77,139.03 +2.73%
ETH $2,421.42 +3.14%
BNB $642.95 +1.15%
XRP $1.48 +1.64%
SOL $88.83 -0.17%
TRX $0.3279 +0.30%
DOGE $0.0995 +0.33%
ADA $0.2587 -0.23%
BCH $453.77 -0.43%
LINK $9.61 +0.56%
HYPE $44.55 +1.56%
AAVE $115.26 -0.10%
SUI $1.00 -0.30%
XLM $0.1743 +3.05%
ZEC $328.92 -3.20%
BTC $77,139.03 +2.73%
ETH $2,421.42 +3.14%
BNB $642.95 +1.15%
XRP $1.48 +1.64%
SOL $88.83 -0.17%
TRX $0.3279 +0.30%
DOGE $0.0995 +0.33%
ADA $0.2587 -0.23%
BCH $453.77 -0.43%
LINK $9.61 +0.56%
HYPE $44.55 +1.56%
AAVE $115.26 -0.10%
SUI $1.00 -0.30%
XLM $0.1743 +3.05%
ZEC $328.92 -3.20%

slow

Slow Fog: Pay attention to checking for malicious versions of axios and the exposure risk of global installation history for OpenClaw npm

Slow Fog has once again issued a security reminder stating to pay attention to checking for malicious versions of axios and the exposure risk of OpenClaw npm global installation history. [email protected] and [email protected] have been confirmed as malicious versions, both of which have injected the dependency [email protected], delivering cross-platform malicious payloads through the postinstall script.The impact of OpenClaw is assessed based on scenarios: source code builds are not affected, as the locked versions in the lock file are 1.13.5/1.13.6; however, users who installed via npm install -g [email protected] face historical exposure risks due to the presence of optionalDependencies.axios@^1.7.4 in the dependency chain, which may resolve to [email protected] during the time window when the malicious version is still online. Currently, npm has reverted the resolution to [email protected], but environments that were installed during the attack window are still advised to be checked. Slow Fog has provided inspection commands and IoC paths for various platforms; if the plain-crypto-js directory is found, even if the package.json has been cleaned, it should still be regarded as high-risk execution traces. It is recommended that affected hosts immediately rotate credentials and conduct host-side inspections. Previously, Slow Fog founder Yu Xian reminded that OpenClaw version 3.28 may introduce a toxic version of axios, and users need to urgently check.

Slow Fog and Bitget release AI Agent security report, the security boundaries behind "lobster-style" automated trading

As the application of AI Agents in cryptocurrency trading rapidly heats up, automated trading is transitioning from "tool-assisted" to "autonomous execution." However, at the same time, a series of security risks are also emerging. Recently, the security agency SlowMist and the exchange Bitget jointly released an AI Agent security report, systematically outlining the potential threats and protective systems for Agent automated trading in the current Web3 scenario.The report combines real cases and security research to analyze the typical security issues faced by AI Agents today, including risks of behavioral manipulation caused by Prompt Injection, supply chain vulnerabilities in plugins and Skill ecosystems, abuse of API Keys and account permissions, as well as potential threats from automated execution leading to operational errors and permission escalation.The report recommends that users effectively control permissions when using AI Agents for trading, by isolating through sub-accounts, setting API IP whitelists, and establishing continuous trading monitoring and anomaly alert mechanisms. Additionally, it suggests introducing manual confirmation or independent signature mechanisms for high-risk operations to prevent model misjudgments from directly affecting asset security. To facilitate users in implementing security measures, the report includes a trading security self-checklist at the end, helping users quickly identify security risks.From an industry development perspective, AI Agents are continuously driving the intelligence of Web3 trading, but the construction of security systems still needs to be upgraded in parallel. Establishing a balance between efficiency and controllability will become an important topic of long-term concern for the industry.
app_icon
ChainCatcher Building the Web3 world with innovations.