News linked to both this project and an event.
According to monitoring by blockchain security company SlowMist (@SlowMist_Team), its threat intelligence system MistEye detected a large-scale npm supply chain attack targeting the Keyv/Cacheable ecosystem. The attackers published over 2,000 malicious package versions in total, involving core components such as [email protected]. As a widely used key-value storage abstraction library, Keyv supports multiple backends including Redis, SQLite, PostgreSQL, and MongoDB, with weekly downloads reaching approximately 127 million, posing significant downstream supply chain exposure risks. This attack method is highly similar to the previous Shai-Hulud npm worm activity, characterized by high automation and scale. Potential risks include credential theft, environment variable leakage, CI/CD key leakage, remote payload delivery, and lateral penetration. SlowMist recommends security teams immediately investigate and remove affected package versions, upgrade to verified secure versions, review dependency lock files and build logs, monitor suspicious outbound connections, rotate exposed credentials, and rebuild relevant environments from trusted sources if intrusion is suspected.
According to CryptoQuant Head of Research Julio Moreno (@jjcmoreno), following the hack of Coldcard hardware wallets, users transferred Bitcoin on a large scale due to security concerns. On-chain data shows that Bitcoin daily active addresses surged from 645,000 on July 30 to nearly 1 million on July 31, marking the highest single-day level since December 10, 2024, with active sending addresses rising significantly while receiving addresses saw relatively limited growth. Meanwhile, daily exchange deposit volume for single transactions under 10 BTC soared to 7,300 BTC, the highest since February 6 this year.