Scan to download
BTC $61,534.22 +0.90%
ETH $1,593.72 +0.97%
BNB $579.23 +0.59%
XRP $1.11 +0.50%
SOL $63.48 -1.34%
TRX $0.3239 +1.04%
DOGE $0.0832 +1.03%
ADA $0.1608 +0.99%
BCH $219.00 +2.82%
LINK $7.53 +1.95%
HYPE $58.10 -3.78%
AAVE $62.09 -0.16%
SUI $0.7426 +3.26%
XLM $0.2156 +8.25%
ZEC $383.06 +0.59%
BTC $61,534.22 +0.90%
ETH $1,593.72 +0.97%
BNB $579.23 +0.59%
XRP $1.11 +0.50%
SOL $63.48 -1.34%
TRX $0.3239 +1.04%
DOGE $0.0832 +1.03%
ADA $0.1608 +0.99%
BCH $219.00 +2.82%
LINK $7.53 +1.95%
HYPE $58.10 -3.78%
AAVE $62.09 -0.16%
SUI $0.7426 +3.26%
XLM $0.2156 +8.25%
ZEC $383.06 +0.59%

supply

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

Bitmine's latest holdings reached 5.39 million ETH, accounting for 4.47% of the supply, with total assets of $12.3 billion. Metaplanet issued 8 billion yen in bonds on April 24 to continue increasing its BTC holdings, maintaining a total of 40,177 coins

According to BBX data, yesterday (May 26), the largest publicly traded company holding Ethereum announced the latest SEC filing, with Strive's weekly increase of 1,109 coins maintaining a steady pace, and the SATA financing flywheel continuing to operate. The core dynamics are as follows:Bitmine Immersion Technologies, Inc. (NYSE: $BMNR) submitted Form 8-K to the SEC on May 26, disclosing that as of that date, the company's ETH holdings reached 5.39 million coins (accounting for 4.47% of the total ETH circulation, with a target of 5%, currently completed 89%), with a total of approximately $12.3 billion in combined crypto assets, cash, and strategic equity investments; among which 4,712,917 ETH has been staked (valued at approximately $10.1 billion at $2,134 per coin), with a 7-day staking annualized yield of 2.75%, and an estimated annualized income of approximately $276 million based on full staking; the company's self-operated validation node platform MAVAN has also opened staking services to external institutions. Chairman Tom Lee pointed out in a statement that if the ETH closing price in May is above $2,100, it will be the first time there has been a positive monthly close for three consecutive months, "which has never happened in a crypto bear market." The average daily trading volume of $BMNR over the past 5 days is approximately $572 million, making it the 193rd most actively traded stock in the U.S.Strive, Inc. (NASDAQ: ASST) disclosed in its 8-K on May 26 the asset changes from May 18-22: BTC holdings increased from 15,391 coins to 16,500 coins (a net increase of 1,109 coins), cash increased from $87.3M to $93.3M (+$6M), and STRC holdings increased from $49.8M to $50.1M; during the same period, Class A common stock increased by approximately 2.23 million shares (conversion of SATA preferred stock), and the total amount of SATA preferred stock increased by approximately 515,000 shares. Strive uses the issuance of SATA preferred stock as its main financing tool, continuing the systematic accumulation of BTC; the BTC yield from 2026 to date is approximately 18.4% (as of May 19).

The security incidents at GitHub and Grafana are likely related to a large-scale "mini sandworm" supply chain attack

According to the threat intelligence released by Slow Fog, several high-frequency npm packages including AntV and Echarts-for-react, as well as the Python SDK durabletask, have recently been targeted by the Mini Shai-Hulud "mini sandworm" supply chain attack. The npm account atool was compromised, and the attacker automatically published 637 malicious versions within 22 minutes, affecting 317 packages. The attacker continuously uploaded durabletask versions 1.4.1, 1.4.2, and 1.4.3 within 35 minutes, bypassing normal release controls and impersonating an official Microsoft release.The large-scale leak of GitHub tokens and the ransomware attack on Grafana Labs are likely related to this supply chain attack. Affected components include high-frequency components such as AntV and Echarts-for-react in the npm ecosystem, as well as Python packages durabletask 1.4.1, 1.4.2, and 1.4.3. Attackers can steal cloud and local credentials, gain unauthorized access to internal repositories and sensitive cloud infrastructure, move laterally to developer machines and CI/CD pipelines, sell and exploit leaked GitHub tokens, and implement ransom and data leak threats.Slow Fog recommends immediately rotating all exposed credentials, replacing affected packages, isolating potentially infected systems, and implementing strict dependency review policies. Previously, it was reported that the "mini sandworm" worm had recently completed widespread infection in open-source code repositories, and developers should be vigilant in checking for issues.

Data: Four on-chain signals indicate that Bitcoin supply is tightening and selling pressure is exhausted

Binance Research released a chart analysis this week indicating that four on-chain signals point to the same conclusion: supply is tightening, and selling pressure has been exhausted.Long-term dormancy: Nearly 60% of BTC supply has not moved for over a year, significantly higher than 27% in 2012. The dormancy rate peaked at 69.5% when the spot Bitcoin ETF was approved in January 2024 and has since remained close to historical highs.SLRV indicator: The short-term to long-term holder value ratio is deeply entrenched in historical bottom territory, indicating a lack of market sentiment. Long-term holders dominate the supply, while short-term speculators have largely exited. Historically, every cycle bottom has been accompanied by this ratio entering the current region.Exchange balances: Since peaking at 17.6% during the pandemic, exchange balances have dropped to 15%, with approximately 500,000 BTC permanently leaving exchanges, and seller supply has fallen to a six-year low.STH MVRV indicator: Since November 2024, the BTC short-term holder MVRV has mostly remained below 1, gradually exhausting selling pressure. Currently, this ratio has rebounded to 1, and short-term holders are beginning to reaccumulate unrealized gains. As profit accumulation is still in its early stages, a new wave of selling pressure is unlikely to emerge immediately; historically, this pattern often appears before a sustained recovery.
app_icon
ChainCatcher Building the Web3 world with innovations.