• bitcoinBitcoin (BTC) $ 61,674.00
  • ethereumEthereum (ETH) $ 1,726.14
  • tetherTether (USDT) $ 0.998820
  • bnbBNB (BNB) $ 563.02
  • usd-coinUSDC (USDC) $ 0.999873
  • xrpXRP (XRP) $ 1.10
  • solanaSolana (SOL) $ 80.95
  • tronTRON (TRX) $ 0.319421
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • hyperliquidHyperliquid (HYPE) $ 67.69
  • dogecoinDogecoin (DOGE) $ 0.074868
  • rainRain (RAIN) $ 0.015554
  • usdsUSDS (USDS) $ 0.999675
  • leo-tokenLEO Token (LEO) $ 9.12
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 447.23
  • stellarStellar (XLM) $ 0.200971
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • whitebitWhiteBIT Coin (WBT) $ 55.75
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • cardanoCardano (ADA) $ 0.166856
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 318.01
  • chainlinkChainlink (LINK) $ 7.78
  • canton-networkCanton (CC) $ 0.138527
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • daiDai (DAI) $ 0.999701
  • usd1-wlfiUSD1 (USD1) $ 0.998493
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.68
  • susdssUSDS (SUSDS) $ 1.08
  • bitcoin-cashBitcoin Cash (BCH) $ 224.42
  • ethena-usdeEthena USDe (USDE) $ 0.998470
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • litecoinLitecoin (LTC) $ 43.32
  • hedera-hashgraphHedera (HBAR) $ 0.071199
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • wethWETH (WETH) $ 2,268.37
  • global-dollarGlobal Dollar (USDG) $ 0.999956
  • suiSui (SUI) $ 0.741216
  • avalanche-2Avalanche (AVAX) $ 6.84
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999803
  • crypto-com-chainCronos (CRO) $ 0.057387
  • nearNEAR Protocol (NEAR) $ 1.96
  • tether-goldTether Gold (XAUT) $ 4,158.48
  • shiba-inuShiba Inu (SHIB) $ 0.000004
  • labLAB (LAB) $ 7.98
  • memecoreMemeCore (M) $ 1.79
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bittensorBittensor (TAO) $ 213.63
  • uniswapUniswap (UNI) $ 3.21
  • pax-goldPAX Gold (PAXG) $ 4,162.43
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.057236
  • aster-2Aster (ASTER) $ 0.639255
  • okbOKB (OKB) $ 80.53
  • ripple-usdRipple USD (RLUSD) $ 0.999901
  • ondo-financeOndo (ONDO) $ 0.329395
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • worldcoin-wldWorldcoin (WLD) $ 0.418483
  • polkadotPolkadot (DOT) $ 0.858020
  • mantleMantle (MNT) $ 0.432990
  • falcon-financeFalcon USD (USDF) $ 0.995706
  • skySky (SKY) $ 0.059283
  • usddUSDD (USDD) $ 0.997715
  • bfusdBFUSD (BFUSD) $ 0.998291
  • aaveAave (AAVE) $ 86.39
  • pi-networkPi Network (PI) $ 0.117864
  • morphoMorpho (MORPHO) $ 1.97
  • internet-computerInternet Computer (ICP) $ 2.23
  • bitget-tokenBitget Token (BGB) $ 1.70
  • ethereum-classicEthereum Classic (ETC) $ 7.14
  • dexeDeXe (DEXE) $ 22.76
  • pepePepe (PEPE) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 0.999702
  • quant-networkQuant (QNT) $ 67.73
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • kucoin-sharesKuCoin (KCS) $ 7.12
  • blockchain-capitalBlockchain Capital (BCAP) $ 106.97
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • usdgoUSDGO (USDGO) $ 0.999851
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • audieraAudiera (BEAT) $ 2.78
  • stable-2​​Stable (STABLE) $ 0.035533
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.13
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • kaspaKaspa (KAS) $ 0.030796
  • render-tokenRender (RENDER) $ 1.62
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • cosmosCosmos Hub (ATOM) $ 1.59
  • jupiter-exchange-solanaJupiter (JUP) $ 0.241667
  • wbnbWrapped BNB (WBNB) $ 759.61
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.073553
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.087470
  • nexoNEXO (NEXO) $ 0.775272
  • justJUST (JST) $ 0.088766
  • adi-tokenADI (ADI) $ 5.88
  • usdtbUSDtb (USDTB) $ 1.00
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • gatechain-tokenGate (GT) $ 6.76
  • ethenaEthena (ENA) $ 0.077253
  • beldexBeldex (BDX) $ 0.088178
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.691523
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.15
  • venice-tokenVenice Token (VVV) $ 13.86
  • pump-funPump.fun (PUMP) $ 0.001555
  • filecoinFilecoin (FIL) $ 0.781951
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ghoGHO (GHO) $ 0.998049
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • flare-networksFlare (FLR) $ 0.006789
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.028548
  • usual-usdUsual USD (USD0) $ 0.998533
  • yldsYLDS (YLDS) $ 0.999733
  • clbtcclBTC (CLBTC) $ 76,920.00
  • midnight-3Midnight (NIGHT) $ 0.031823
  • hash-2Provenance Blockchain (HASH) $ 0.009588
  • aptosAptos (APT) $ 0.619772
  • lighterLighter (LIT) $ 2.06
  • usxUSX (USX) $ 0.999988
  • arbitrumArbitrum (ARB) $ 0.078355
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • true-usdTrueUSD (TUSD) $ 0.997652
  • aerodrome-financeAerodrome Finance (AERO) $ 0.509765
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • a7a5A7A5 (A7A5) $ 0.012377
  • tbtctBTC (TBTC) $ 70,942.00
  • injective-protocolInjective (INJ) $ 4.78
  • euro-coinEURC (EURC) $ 1.15
  • dashDash (DASH) $ 35.47
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.37
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006719
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.186903
  • official-trumpOfficial Trump (TRUMP) $ 1.75
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.76
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • vechainVeChain (VET) $ 0.004681
  • hastra-primeHastra PRIME (PRIME) $ 1.05
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • bonkBonk (BONK) $ 0.000004
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.564163
  • cocaCOCA (COCA) $ 1.30
  • jito-governance-tokenJito (JTO) $ 0.753459
  • celestiaCelestia (TIA) $ 0.392938
  • spx6900SPX6900 (SPX) $ 0.390583
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996797
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000062
  • sei-networkSei (SEI) $ 0.049409
  • apxusdapxUSD (APXUSD) $ 0.865533
  • the9bitThe9bit (9BIT) $ 0.042627
  • grassGrass (GRASS) $ 0.507902
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • kinesis-goldKinesis Gold (KAU) $ 133.84
  • sun-tokenSun Token (SUN) $ 0.016605
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • ether-fiEther.fi (ETHFI) $ 0.339723
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • curve-dao-tokenCurve DAO (CRV) $ 0.204576
  • blockstackStacks (STX) $ 0.168873
  • pyth-networkPyth Network (PYTH) $ 0.039428
  • bitcoin-svBitcoin SV (BSV) $ 14.00
  • gnosisGnosis (GNO) $ 104.56
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • kite-2Kite (KITE) $ 0.109513
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • ethgas-2ETHGas (GWEI) $ 0.124160
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • noonNoon (NOON) $ 0.751949
  • apenftAINFT (NFT) $ 0.00000026
  • royal-dollarRoyal Dollar (RUSD) $ 0.998700
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • pendlePendle (PENDLE) $ 1.50
  • plasmaPlasma (XPL) $ 0.098467
  • build-onBUILDon (B) $ 0.248518
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • olympusOlympus (OHM) $ 16.68
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • tezosTezos (XTZ) $ 0.222449
  • monadMonad (MON) $ 0.020291
  • fraxLegacy Frax Dollar (FRAX) $ 0.990066
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • kinesis-silverKinesis Silver (KAG) $ 62.45

Expert Warns of Critical, Ongoing Supply Chain Attack on Axios

0 1


According to Feross Aboukhadijeh, co-founder of security-oriented firm Socket Security, there is an active supply chain on Axios, which is one of npm’s most depended-on packages.

NPM stands for Node Package Manager and is basically the world’s largest software registry, hosting more than two million packages of open-source JavaScript code. An argument can be made that it’s the backbone of modern Web3 development.

According to Feross, the latest axios@1.14.1 is currently pulling in plain-crypto-just@4.2.1, which is a package that did not exist before today, suggesting that it’s a live compromise.

This is textbook supply chain installer malware. Axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analyiss confirms this is malware. Plain-crypto-js is an obfuscated dropper/loadre.”

The malicious software can perform a range of actions, including deleting and renaming artifacts post-execution to destroy forensic evidence, staging and copying payload files to the OS temp and Windows ProgramData directories, executing decoded shell commands, and more.

🚨 CRITICAL: Active supply chain attack on axios — one of npm’s most depended-on packages.

The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.

This is textbook supply chain installer malware. axios…

— Feross (@feross) March 31, 2026

The expert recommends that developers who use axios immediately pin their versions and audit their lockfiles, while refraining from any updates for the time being.



Source link

Leave A Reply

Your email address will not be published.