R-Sync 同期🦀🗿
126.1K posts

R-Sync 同期🦀🗿
@RSync25
₿itcoiner, Mid-level Engineer & Building AI & Robotic Labs #npub1c8l997847szpt6prwug6usmfl48v7afun9d4zt6f5xexhrdps45sctmg0w


A Context.ai employee's machine got hit by an infostealer on February 17. Three months later, ShinyHunters announced they had breached Vercel. Vercel Breach Potentially Traced Back to Infostealer Malware: whiteintel.io/blog/vercel-br…




We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin: vercel.com/kb/bulletin/ve…



🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.












Congress is trying to sneak a CBDC into their must-pass housing bill. It would replace the US dollar with a government-controlled crypto-token that 80% of voters reject.







