Downloads – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 08 Jun 2025 03:54:05 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Downloads – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Supply chain attack hits Gluestack NPM packages with 960K weekly downloads https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/ https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/#respond Sun, 08 Jun 2025 03:54:04 +0000 https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/

NPM

A significant supply chain attack hit NPM after 16 popular Gluestack ‘react-native-aria’ packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT).

BleepingComputer determined that the compromise began on June 6 at 4:33 PM EST, when a new version of the react-native-aria/focus package was published to NPM. Since then, 16 of the 20 Gluestack react-native-aria packages have been compromised on NPM, with the threat actors publishing a new version as recently as two hours ago.

Ongoing compromise of NPM packages
Ongoing compromise of NPM packages
Source: BleepingComputer

The supply chain attack was discovered by cybersecurity firm Aikido Security, who discovered obfuscated code injected into the lib/index.js file for the following packages:

Package Name Version Weekly Downloads
react-native-aria/button 0.2.11 51,000
react-native-aria/checkbox 0.2.11 81,000
react-native-aria/combobox 0.2.10 51,000
react-native-aria/disclosure 0.2.9 3
react-native-aria/focus 0.2.10 100,000
react-native-aria/interactions 0.2.17 125,000
react-native-aria/listbox 0.2.10 51,000
react-native-aria/menu 0.2.16 22,000
react-native-aria/overlays 0.3.16 96,000
react-native-aria/radio 0.2.14 78,000
react-native-aria/switch 0.2.5 477
react-native-aria/toggle 0.2.12 81,000
react-native-aria/utils 0.2.13 120,000
gluestack-ui/utils 0.1.17 55,000
react-native-aria/separator 0.2.7 65
react-native-aria/slider 0.2.13 51,000

These packages are very popular, with approximately 960,000 weekly downloads, making this a supply chain attack that could have widespread consequences.

The malicious code is heavily obfuscated and is appended to the last line of source code in the file, padded with many spaces, so it’s not easily spotted when using the code viewer on the NPM site.

Malicious code added to end of index.js file
Malicious code added to end of index.js file
Source: BleepingComputer

Aikido told BleepingComputer that the malicious code is nearly identical to a remote access trojan in another NPM compromise they discovered last month.

The researcher’s analysis of the previous campaign explains that the remote access trojan will connect to the attackers’ command and control server and receive commands to execute.

These commands include:

  • cd – Change current working directory
  • ss_dir – Reset directory to script’s path
  • ss_fcd: – Force change directory to
  • ss_upf:f,d – Upload single file f to destination d
  • ss_upd:d,dest – Upload all files under directory d to destination dest
  • ss_stop – Sets a stop flag to interrupt current upload process
  • Any other input – Treated as a shell command, executed via child_process.exec()

The trojan also performs Windows PATH hijacking by prepending a fake Python path (%LOCALAPPDATA%\Programs\Python\Python3127) to the PATH environment variable, allowing the malware to silently override legitimate python or pip commands to execute malicious binaries.

Aikido sercurity researcher Charlie Eriksen has attempted to contact Gluestack about the compromise by creating GitHub issues on each of the project’s repositories, but there has not been any response at this time.

“No response from package maintainers (it’s morning on a saturday in the US which is prob exactly why its happening now),” Arkido told BleepingComputer.

“NPM we have contacted and reported each package, this is a process that usually takes multiple days for NPM to address though.”

Aikido also attributes this attack to the same threat actors who compromised four other NPM packages earlier this week named biatec-avm-gas-stationcputil-nodelfwfinance/sdk, and lfwfinance/sdk-dev.

BleepingComputer reached out to Gluestack about the compromised packages but has not received a reply at this time.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/supply-chain-attack-hits-gluestack-npm-packages-with-960k-weekly-downloads/feed/ 0 40780
South Korea Freezes DeepSeek Downloads Over Data Handling Fears https://earlybirdsinvest.com/south-korea-freezes-deepseek-downloads-over-data-handling-fears/ https://earlybirdsinvest.com/south-korea-freezes-deepseek-downloads-over-data-handling-fears/#respond Wed, 19 Feb 2025 00:28:19 +0000 https://earlybirdsinvest.com/south-korea-freezes-deepseek-downloads-over-data-handling-fears/

South Korea has temporarily blocked new downloads of DeepSeek, an artificial intelligence (AI) chatbot developed by a Chinese company, while authorities investigate how it handles user data.

Following DeepSeek’s launch, the country’s Personal Information Protection Commission (PIPC) began reviewing its data policies and sent inquiries to DeepSeek regarding its collection and processing of personal information.

The commission has identified issues in how the app communicates with third-party services and manages user data, some of which have been reported by media outlets in South Korea and internationally.

What is an NFT? (Explained with Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

On February 17, the PIPC announced the decision, stating that DeepSeek agreed to pause new installations on February 15 and will work with regulators to strengthen its privacy protections before resuming.

While new users cannot download the app, those who already have it can continue using it. However, the PIPC advises caution until the investigation is complete. The agency plans to review how DeepSeek collects and processes personal data to ensure it complies with South Korea’s privacy laws.

To make sure DeepSeek follows South Korea’s data protection rules, the PIPC will conduct on-site checks. They want to see how DeepSeek keeps and uses existing users’ data. They will also give advice to help DeepSeek meet local laws and to help other AI companies avoid similar problems.

Recently, Microsoft and OpenAI investigated the Chinese AI company DeepSeek. What were the allegations against the company? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/south-korea-freezes-deepseek-downloads-over-data-handling-fears/feed/ 0 20386