Solriah

2.9K posts

Solriah banner
Solriah

Solriah

@Solriah

Community lead @ProAgentAI | $PRO | Building @liquidityranger | UI/UX Designer 💎

เข้าร่วม Şubat 2022
1K กำลังติดตาม656 ผู้ติดตาม
ทวีตที่ปักหมุด
Solriah
Solriah@Solriah·
We're proud to announce that $PRO tokens are now fully integrated into our play-to-learn-to-earn video game, "LIQUIDITY RANGER" launching soon on @farcaster_xyz.
Solriah tweet media
English
6
8
34
2K
Toady Hawk
Toady Hawk@toady_hawk·
if anybody needs me I’ll be out clanking my shit ✌🏼
Toady Hawk tweet media
English
10
1
27
3.7K
10FIGS
10FIGS@iapecooks·
@Solriah And you dey let me suffer
10FIGS tweet media
English
1
0
2
61
10FIGS
10FIGS@iapecooks·
How much do you spend on data monthly?
10FIGS tweet media
English
19
1
32
653
Solriah
Solriah@Solriah·
Playing against people not the house, and against people I win 🏆
English
0
0
6
28
Solriah รีทวีตแล้ว
klöss
klöss@kloss_xyz·
do you understand what just happened to one of the most used npm packages on the internet? → axios gets downloaded over 100 million times a week and today it got compromised → an attacker hijacked the npm credentials of a lead axios maintainer… changed the account email to an anonymous ProtonMail address… and manually published two poisoned versions → axios@1.14.1 and axios@0.30.4… neither version contains a single line of malicious code inside axios itself. instead they inject a fake dependency called plain-crypto-js that drops a remote access trojan on your machine → the fake dependency was staged 18 hours in advance… three separate payloads were pre-built for macOS, Windows, and Linux… both release branches were hit within 39 minutes. every trace was designed to self-destruct after execution too → there’s no tag in the axios GitHub repo for 1.14.1. it was published outside the normal release process entirely... bypassed CI/CD completely → StepSecurity called it one of the most operationally sophisticated supply chain attacks ever against a top 10 npm package → a routine npm install silently opens a backdoor… no warning… no suspicious code visible in axios itself this is the wake up call all vibe coding bros need to hear right now: → if you installed either version… assume your system is compromised → pin to axios@1.14.0 or axios@0.30.3 → rotate all secrets, API keys, SSH keys, and credentials on affected machines → check network logs for C2 connections → add –ignore-scripts to CI npm installs going forward 100 million weekly downloads and one compromised maintainer account… that’s all it took to wreak absolute havoc and I imagine we see a whole lot more of these… crazy times ahead for cybersecurity and vibe coding be safe out there y’all
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
107
488
3.5K
864K
Solriah รีทวีตแล้ว
Liquidity Ranger
Liquidity Ranger@Liquidityranger·
March wrapped 🔁 Thousands of Rangers jumped in this month, nearly 6,000 opens, over 2,500 onchain transactions, close to 1,000 Rangers added the mini app, with rewards of over $250 distributed in $PRO. We hit #14 globally on farcaster.🎉 Happy Ranging into the new month 🧑‍🚀🚀
Liquidity Ranger tweet media
English
2
2
7
68
ntare ivan
ntare ivan@NtareIvan·
Nature’s defense system in perfect
English
344
326
3.7K
5.3M
Zen
Zen@zenonchain·
Your reward is in heaven
Zen tweet media
English
3
5
40
630
Zen
Zen@zenonchain·
@Solriah Na so we Dey see am 😂
English
1
0
1
74
Solriah
Solriah@Solriah·
I’ll personally go after some fintech apps when the time is right. This can’t be happening 🤦🏾‍♂️ Smh
English
0
0
4
44
10FIGS
10FIGS@iapecooks·
It's a Saturday morning, what did you have for breakfast?
10FIGS tweet media
English
29
3
39
1K
10FIGS
10FIGS@iapecooks·
@Solriah My opay dey your dm no whine me🙂‍↔️😂
English
1
0
2
26
10FIGS
10FIGS@iapecooks·
@Solriah do giveaway for me Dad🙂‍↔️
English
1
0
0
35
whizz 🍫
whizz 🍫@whizz_xD·
ogbono girls are easy to crack
English
73
1
145
5.4K