
CompleteTech
16 posts



🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.


We also found two additional packages with the same payloads: @shadanai/openclaw (malware hidden in vendored path) and @qqbrowser/openclaw-qbot (ships pre-populated node_modules with the compromised axios baked in). Same C2, same payloads. Brings the total number of affected packages to 4.






🚨GROK 3 SENDS USAGE SOARING – 10X SPIKE IN DOWNLOADS Elon’s xAI just dropped Grok 3, and the numbers are wild. Mobile downloads exploded 10X the week it launched, with daily U.S. users up 260%. Even Grok’s web app visits shot from 189K to over 900K a day. Globally? 4.5 million hits daily. Some of that boom came from expanding into Europe, Latin America, and Southeast Asia, but Grok 3 clearly grabbed attention fast. Source: TechCrunch















