ended6월 5일· 1 sources
How GitHub Tokens Became the Key to Crypto Wallet Theft
개발자 토큰을 무기화한 NPM 공격, 암호화폐 지갑까지 위협한다
Why it matters
This supply chain attack leverages the trust developers place in npm packages to steal GitHub credentials and inject malware into repositories. For crypto and DeFi projects, the consequences are uniquely severe—compromised websites can drain user wallets within minutes, making this one of the most financially damaging supply chain attacks to date. The automated propagation, which infects thousands of projects in hours, reveals how rapidly vulnerabilities in shared dependencies can scale across the entire ecosystem.
1
Sources
+0
24h
—
Growth
5d
Active
GitHub tokensNPM packagesCrypto walletsMalwareDeFi