
Coldlar Wallet 库神钱包
796 posts

Coldlar Wallet 库神钱包
@Coldlar_cn
库神钱包|冷存储专家,终极安全保障 CCEAL6+ 军工级安全芯片|物理隔离安全机制|支持多链与 NFT


🚨 SlowMist TI Alert 🚨 Please check for Malicious Versions of #axios 1.14.1 / 0.30.4 and Historical Exposure Risk from global #OpenClaw npm Installation. As of March 31, 2026, open-source intelligence indicates that axios@1.14.1 and axios@0.30.4 have been confirmed as malicious versions. Both contain an extra dependency, plain-crypto-js@4.2.1, which can deliver cross-platform malicious payloads via its postinstall script. 1️⃣/ The impact on OpenClaw needs to be assessed per scenario: 1) Source Build Scenario: Not Affected 🤖 👉 Lock files in v2026.3.28 actually lock axios@1.13.5 / 1.13.6, which are not malicious versions. 2) npm install -g openclaw@2026.3.28 Scenario: Historical Exposure Risk Exists 🔍 👉 This is because the dependency chain includes: openclaw -> @line/bot-sdk@10.6.0 -> optionalDependencies.axios@^1.7.4 During the time window when the malicious versions were online, axios@1.14.1 could have been resolved. 3) Current Reinstallation Result: npm now resolves to axios@1.14.0 🧩 👉 However, environments that installed within the attack window should still be treated according to the affected scenario, and IoC checks are recommended. 2️⃣/ Reference for Checks ✅ Check for malicious versions and modules first: npm list axios 2>/dev/null | grep -E "1.14.1|0.30.4" grep -A1 '"axios"' package-lock.json 2>/dev/null | grep -E "1.14.1|0.30.4" ls node_modules/plain-crypto-js 2>/dev/null && echo "POTENTIALLY AFFECTED" ✅ If OpenClaw was installed globally, also check the global path: npm root -g npm ls -g openclaw axios plain-crypto-js @ line/bot-sdk --depth=4 3️⃣/ Known IoC Path Checks #macOS ls -la /Library/Caches/com.apple.act.mond 2>/dev/null && echo "COMPROMISED" #Linux ls -la /tmp/ld.py 2>/dev/null && echo "COMPROMISED" #Windows (cmd.exe) dir "%PROGRAMDATA%\wt.exe" 2>nul && echo COMPROMISED 4️⃣/ Additional Notes If the plain-crypto-js directory exists, even if its package.json has been cleaned, it should still be treated as a high-risk execution trace. ⚠️ For hosts that executed npm install or npm install -g openclaw@2026.3.28 within the attack window, immediate credential rotation and host-side investigation are recommended.

很有趣的一个对比,受 Apifox 供应链投毒攻击影响的人或公司,意识到问题严重性的,都在排查解决,没有一个去找 Apifox 维权损失的,而如果这个玩意是加密行业流行的,维权的人就多了。 当然,被骂都是不可避免的。







Crypto HK 現正式宣布將庫神 @Coldlar_en @Coldlar_cn 加入冷錢包銷售陣容🔒 作為九大冷錢包品牌的合作夥伴,Crypto HK 致力為用戶帶來更安心、更多元的選擇。 庫神 為香港本土品牌,其Ultra型號硬件錢包搭載CC EAL6+等級安全晶片,私鑰全程保持離線、不接觸網路。設備配備5英寸彩色觸控螢幕及後置1300萬像素相機。支援多條區塊鏈管理,待機時間最長可達20天,機身採用鋅合金材質,具備一定程度的側通道攻擊防護設計。 As a partner of nine major cold wallet brands, Crypto HK is committed to offering users enhanced security assurance and a broader range of options. ColdLar, a Hong Kong-based brand, features the ColdLar Ultra equipped with a CC EAL6+ certified secure element chip. The private key remains fully offline and never connects to the internet throughout its lifecycle. The device includes a 5-inch color touchscreen and a rear 13-megapixel camera. It supports management of multiple blockchains, provides up to 20 days of standby time, and features a zinc alloy body with designs offering protection against certain side-channel attacks. 感興趣的用戶可 Whatsapp 至 +852 5308 6000 了解詳情及下單🚀 Interested users are welcome to WhatsApp us at +852 5308 6000 for more details and to place your order🚀 以上內容僅供參考,不構成任何財務建議。 The above content is for reference only and does not constitute any financial advice. #CryptoHK #庫神錢包 #ColdLar #冷錢包 #加密安全 #加密貨幣 #HardwareWallet #Cryptocurrency

























