QooryBeta
Back to narratives
SecurityEmerging
Conversation intelligence

Web3 security incident: GitHub 上一个开源交易工具,挂着三百多颗星,放在一个 2019 年就存在的老牌组织底下。你八成会觉得,这总安全了吧? 7 月 1 日,慢雾(SlowMist)把它扒了出来。 一个冒充 Polymarket 交易机器人的项目,看起来人畜无害,实际上是个专偷钱包的木马。 数字先

A fast-moving Web3 discussion is forming around Web3 security incident: GitHub 上一个开源交易工具,挂着三百多颗星,放在一个 2019 年就存在的老牌组织底下。你八成会觉得,这总安全了吧? 7 月 1 日,慢雾(SlowMist)把它扒了出来。 一个冒充 Polymarket 交易机器人的项目,看起来人畜无害,实际上是个专偷钱包的木马。 数字先.

Heat
39
Confidence
70%
Evidence
3
Updated

Why It Happened

Multiple social or news items are discussing the same topic in a short time window.

Actors

香菱香菱1491Project
SlowmistBlockchain security company
RSRST CloudProject
Timeline order

Post
Parent event 01

#threatreport #LowCompleteness The Polymarket Trap: A Fake Arbitrage Bot, Ten npm Accounts, and…

#threatreport #LowCompleteness The Polymarket Trap: A Fake Arbitrage Bot, Ten npm Accounts, and Four Ways to Deliver an Infostealer | 30-06-2026 Source: https://t.co/Ltn0rRL6EY Key details below ↓ 💀Threats: Typosquatting_technique, 🎯Victims: Defi developers…

Related posts@SlowMist_Team@rst_cloud
@SlowMist_TeamOfficial X
Open on X3.4K views · 24 likes · 6 reposts
@rst_cloudOfficial X
Open on X109 views · 1 likes · 0 reposts

Post
Parent event 02

主流媒体转述安全公告

吴说区块链 (@wublockchain12) 转述慢雾公告,总结攻击细节:涉及 30 个恶意 npm 包,仓库有约 2300 个高度同质、疑似批量生成的 fork。攻击行为包括窃取钱包 vault、浏览器 cookie、已保存密码、私钥等。

Related posts

Post
Parent event 03

安全社区发布详细分析

安全研究员 @mandicoin1491 发布详细分析,指出该攻击冒充 Polymarket 交易机器人,含有 300 多颗星和 300 多个 fork(大部分是机器人刷的),至少 53 位真实开发者被骗运行。攻击者疑似北韩黑客组织 Contagious Trader。

Related posts@mandicoin1491
@mandicoin1491Official X
Open on X920 views · 7 likes · 0 reposts