🚨 SlowMist TI Alert 🚨
MistEye has received critical threat intelligence regarding an active supply chain attack compromising node-ipc, a foundational Node.js library. The malicious releases have been identified as versions 9.1.6, 9.2.3, and 12.0.1.
Threat actors injected an obfuscated credential-stealing payload into the CommonJS bundle. Once loaded, it silently harvests over 90 categories of developer data—including AWS, Azure, GCP, SSH, K8s tokens, and Terraform states—and exfiltrates it to attacker-controlled infrastructure. We have synchronized this IOC with our clients immediately.
Detection & Remediation:
Please urgently audit your environments for exposure:
• Dependencies: Run npm ls node-ipc --all to identify direct or transitive inclusions.
• Lockfiles: Search package-lock.json, yarn.lock, or pnpm-lock.yaml for the affected version ranges.
• CI/CD: Review pipeline jobs executed after May 14, 2026, that may have pulled loose semver updates (~9.1.x, ^12, etc.).
⚠️ Critical Action: If a compromised version was installed, assume certain compromise. Do not wait for exfiltration confirmation. Downgrade to a known safe version immediately and aggressively rotate all credentials, tokens, and environment secrets present on the affected machine or CI runner.
As always, stay vigilant!
显示更多
郭美:2026年5月13日,不是所有的离别都有准备。
遗憾沉重的告知战友们,我们的爱犬Snow于昨晚病逝。他最后的时间我和妈妈一直陪伴着他,在我们的安抚和祈祷中安静的离开。
Snow是我9年前送给爸爸的生日礼物。从一开始,他就被赋予的是希望和相伴。Snow在这9年的时间,带给我们一家人无数的快乐,风雨飘摇的9年,他全是温暖和爱。谢谢Snow,让我看到了爸爸妈妈更多的笑容和幸福,让我感受到最纯粹的爱与忠诚,让我们有最明亮幸福的回忆。 感谢Snow一路陪伴爆料革命,更加感谢战友们对他的爱。 Snow走了,但没有离开。我们的Snow是爆料革命的一部分,和我们的信念一起,长在骨髓里。
我亲爱的Snow,此刻你已经到达彩虹桥,吐着你的小舌头歪歪脑袋,开心的笑着。愿你吃着你最爱的零食,追着蝴蝶,打着滚儿,看着你喜欢的人们,快乐无忧的当一只乐呵的小狗。 我们会每天想你,每刻念你。谢谢你,给我们你的一切。我们爱你❤️
Until we meet again, my angel 🌈
显示更多