Scan to download
BTC $60,823.60 -0.79%
ETH $1,566.66 -2.05%
BNB $574.41 -0.42%
XRP $1.09 -1.26%
SOL $62.05 -3.68%
TRX $0.3240 +1.12%
DOGE $0.0817 -0.92%
ADA $0.1571 -0.95%
BCH $216.75 +2.32%
LINK $7.38 -0.63%
HYPE $56.51 -6.46%
AAVE $60.69 -3.44%
SUI $0.7191 -0.19%
XLM $0.2117 +3.61%
ZEC $366.39 -7.20%
BTC $60,823.60 -0.79%
ETH $1,566.66 -2.05%
BNB $574.41 -0.42%
XRP $1.09 -1.26%
SOL $62.05 -3.68%
TRX $0.3240 +1.12%
DOGE $0.0817 -0.92%
ADA $0.1571 -0.95%
BCH $216.75 +2.32%
LINK $7.38 -0.63%
HYPE $56.51 -6.46%
AAVE $60.69 -3.44%
SUI $0.7191 -0.19%
XLM $0.2117 +3.61%
ZEC $366.39 -7.20%

slow

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Slow Fog: TRON users should be vigilant against phishing activities involving counterfeit TronLink Chrome extensions

SlowMist has issued a security warning stating that a high-risk phishing activity targeting TRON wallet users has been discovered. Attackers created a fake Chrome extension for the TronLink wallet, using Unicode bidirectional control characters and Cyrillic homographs to disguise the brand name. After installation, the extension loads a complete phishing page through a remote iframe, forming a "shell-core separation" credential theft chain.The malicious extension name uses homographs for disguise, and its Chrome Store page inherits the high user count and positive reviews of the real extension, lowering the review threshold. There is very little local code, only loading remote pages, making static analysis nearly impossible to detect malicious behavior. The remote phishing page perfectly replicates the official TronLink web wallet interface, stealing mnemonic phrases, private keys, Keystore files, and passwords, and relaying them in real-time via a Telegram Bot.Built-in anti-analysis features disable right-click, developer tools, drag-and-drop, and printing, and redirect based on the geographic and language settings of Russian users to evade detection. SlowMist recommends immediately uninstalling suspicious extensions, clearing local storage, checking for abnormal traffic, and if credentials have been entered, creating a new wallet and transferring assets immediately.

ETF capital is driving a slow bull market with positive gamma, and the options rising star trader support program is now open

BTC IV 39%, ETH IV 55%; ETH Skew is at a critical turning point------the mid to long term stabilizes at +2 to +5, while the short term has repeatedly dropped to -10 but quickly returned to zero. If ETH stabilizes above $2,400, the short term turning positive will resonate with the mid to long term, confirming a shift from event hedging to upward chasing. The BTC/ETH GEX Term Structure shows that the near-month Gamma has clearly turned positive, with ETF inflows and Call accumulation driving a positive Gamma slow bull structure------under a Long Gamma environment for market makers, the short term is inclined towards high-level fluctuations and slow increases, with IV retreating. Bull Call Spread and selling Put strategies are dominant, but the far month retains negative Gamma reflecting ongoing tail hedging demand. In terms of block trades, 1,001.8 BTC 5/8 expiration $88K Calls were traded, and 14,288 ETH 5/15 expiration $2,600 Calls were traded, indicating clear bullish signals from institutions.Gate has launched the "Rising Star Trader Support Program" for options, with a total prize pool of $25,000 USDT. During the event, users can earn multiple rewards through options trading, inviting friends, and participating in KOL incubation camps: the highest reward for meeting trading volume standards can reach $3,000, and the highest commission for inviting can reach $2,000. Meanwhile, the platform also provides high-quality traders with 1-on-1 options hedging training, exclusive rate discounts, and traffic support, helping traders enhance their strategy capabilities and market influence, and providing a more competitive trading environment and growth opportunities for professional options users.
app_icon
ChainCatcher Building the Web3 world with innovations.