Z
1.8K posts


Z ری ٹویٹ کیا

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English


网传张雪峰竟然摔倒半小时后才被发现?
户子的含金量还在上升!
我是从来不戴表的人
最近准备买一个Apple watch!
综合各品牌的官方功能和实际使用逻辑来看,目前Apple Watch的跌倒检测整体最成熟,在检测、自动报警、联系急救和通知联系人等环节形成了最完整的闭环,且支持机型范围广、独立性强;安卓阵营中,Google Pixel Watch在自动呼救流程上最接近苹果,但受地区和是否连接手机限制;Samsung Galaxy Watch功能稳定但自动化程度略弱;而华为、小米则存在机型差异较大的问题;Garmin更偏向运动事故检测而非日常跌倒场景,因此整体结论是:苹果最好,其次 Pixel 和三星,其余品牌需具体看型号与使用场景。

中文

🚨如果你在 3 月 4 日之后打开过 Apifox,你的SSH密钥、Git Token、K8s 等配置可能已被窃取。CDN上的 JS文件被注入后门,通过伪装官方域名回传数据,Cloudflare 托管仅存活 18 天。攻击者留下了中文注释,疑似AI开发C2。全平台受影响,立即轮换所有凭据。 这是我的详细分析 rce.moe/2026/03/25/api…
中文





















