Publish – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 24 Jul 2025 15:13:13 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Publish – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hackers breach Toptal GitHub account, publish malicious npm packages https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/ https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/#respond Thu, 24 Jul 2025 15:13:12 +0000 https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/

NPM

Hackers compromised Toptal’s GitHub organization account and used their access to publish ten malicious packages on the Node Package Manager (NPM) index.

The packages included data-stealing code that collected GitHub authentication tokens and then wiped the victims’ systems.

Toptal is a freelance talent marketplace that connects companies with software developers, designers, and finance experts. The company also maintains internal developer tools and design systems, most notably Picasso, which they make available through GitHub and NPM.

Attackers hijacked Toptal’s GitHub organization on July 20, and almost immediately made public all 73 of the repositories available, exposing private projects and source code.

Tweet

In the days that followed, the attackers modified the source code of Picasso on GitHub to include malware and published 10 malicious packages on NPM as Toptal, making them appear as legitimate updates.

The malicious packages and modified versions are:

  • @toptal/picasso-tailwind (v3.1.0)
  • @toptal/picasso-charts (v59.1.4)
  • @toptal/picasso-shared (v15.1.0)
  • @toptal/picasso-provider (v5.1.1)
  • @toptal/picasso-select (v4.2.2)
  • @toptal/picasso-quote (v2.1.7)
  • @toptal/picasso-forms (v73.3.2)
  • @xene/core (v0.4.1)
  • @toptal/picasso-utils (v3.2.0)
  • @toptal/picasso-typography (v4.1.4)

The malicious packages were downloaded roughly 5,000 times before being detected, likely infecting developers with malware.

The hackers injected the malicious code into ‘package.json’ files to add two functions: steal data (‘preinstall’ script) and wipe hosts (‘postinstall’ script).

The first extracts the victim’s CLI authentication token and sends it to an attacker-controlled webhook URL, granting them unauthorized access to the target’s GitHub account.

After exfiltrating the data, the second script attempts to delete the entire filesystem with ‘sudo rm -rf –no-preserve-root /’ on Linux systems, or recursively and silently delete files on Windows.

According to code security platform Socket, Toptal deprecated the malicious packages on July 23 and reverted to safe versions, but issued no public statement to alert users who had downloaded the malicious releases to the risks.

Although the initial compromise method remains unknown, Socket lists multiple possibilities ranging from insider threats to phishing attacks targeting Toptal developers.

BleepingComputer has contacted Toptal for a statement, but we are still waiting for their response.

If you have installed any of the malicious packages, you are advised to revert to a previous stable version as soon as possible.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/feed/ 0 49418
OCC, Fed, FDIC publish joint guidance for banks offering crypto custody https://earlybirdsinvest.com/occ-fed-fdic-publish-joint-guidance-for-banks-offering-crypto-custody/ https://earlybirdsinvest.com/occ-fed-fdic-publish-joint-guidance-for-banks-offering-crypto-custody/#respond Mon, 14 Jul 2025 23:13:43 +0000 https://earlybirdsinvest.com/occ-fed-fdic-publish-joint-guidance-for-banks-offering-crypto-custody/

The Office of the Comptroller of the Currency (OCC), the Federal Reserve Board (Fed), and the Federal Deposit Insurance Corporation (FDIC) released a joint statement explaining how existing banking rules apply when institutions custody crypto for customers. 

The guidance describes “safekeeping” as the act of holding a digital asset on a client’s behalf and stresses that it does not create new supervisory demands.

Risk control centers on cryptographic keys

Regulators instructed boards and executives to view crypto custody as a service that relies on exclusive control of private keys and other sensitive data. They note that a bank must prove no other party, even the customer, can unilaterally move an asset once it enters custody. 

Management must assess how key-generation tools, wallet types, and contingency plans align with the institution’s broader control environment and ensure that staff possess the necessary technical skills to maintain these safeguards.

The statement also told banks to weigh the volatility of the asset class and the rapid pace of technological change when allocating capital and staffing for custody operations. 

The agencies said sound programs include continuous reviews of each supported token’s software dependencies and ledger design to spot vulnerabilities that could threaten safety and soundness.

Compliance, governance, and third-party oversight

The three agencies reminded institutions that crypto custody must satisfy Bank Secrecy Act, anti-money laundering, counter-terrorism financing, and Office of Foreign Assets Control rules, including the “travel rule” that attaches identifying information to transfers. 

Boards must involve the BSA officer and senior managers early in any custody rollout to gauge illicit-finance exposure and document controls. 

Additionally, banks that delegate storage to sub-custodians remain responsible for the performance of those vendors. The guidance instructed firms to examine a sub-custodian’s key management methods, segregation of assets, and insolvency protections before signing contracts.

Firms will also be required to build notice requirements for any breach or operational event. Institutions that keep assets in-house but buy third-party software must apply the same vendor-risk disciplines. 

Finally, the agencies requested that auditors expand their testing to include crypto-specific elements, such as key generation, wallet security, and on-chain settlement controls. 

When internal teams lack expertise, management should hire independent specialists to validate safeguards and report directly to the audit committee.

The joint statement concluded that existing fiduciary, custody, and information security regulations already provide a framework for banks that wish to safeguard their crypto.

However, those banks must demonstrate that they can control keys, manage vendors, and comply with federal financial crime statutes in real time.

]]>
https://earlybirdsinvest.com/occ-fed-fdic-publish-joint-guidance-for-banks-offering-crypto-custody/feed/ 0 47659
Pudgy Penguins and Random House to Publish First Children’s Book https://earlybirdsinvest.com/pudgy-penguins-and-random-house-to-publish-first-childrens-book/ https://earlybirdsinvest.com/pudgy-penguins-and-random-house-to-publish-first-childrens-book/#respond Wed, 21 May 2025 18:21:34 +0000 https://earlybirdsinvest.com/pudgy-penguins-and-random-house-to-publish-first-childrens-book/

Popular web3 brand Pudgy Penguins has partnered with Random House Children’s Books to release a new picture book titled Worst Birthday Gift Ever, due out on 4 November 2025, marking the brand’s first official venture into traditional publishing.

The book will introduce young readers to Pongo, a character from the “Lil Pudgy” sub-collection, in a story aimed at children aged 4 to 8.

Written by Michael Leviton and illustrated by Kuma Labs, the book will be released as a $9.99 hardcover, in time for the holiday season and is now available for pre-order.

Pudgy Penguins and Random House to Publish First Children’s Book
Source: Penguin Random House

What is Worst Birthday Gift Ever all about?

Set in the fictional world of Pudgy Penguins, the book follows the character Pongo as he celebrates his birthday. Known within the Pudgy community as impulsive but well-meaning, Pongo finds himself in trouble after his friends mistakenly give him real swords instead of inflatable ones. The narrative unfolds with a mix of chaos and problem-solving, offering a simple storyline for early readers.

The book is targeted at children between the ages of 4 and 8 and combines traditional picture book elements—humour, character conflict, and resolution—with characters developed within the Pudgy Penguins universe.

“Worst Birthday Gift Ever is more than a book – it’s the next chapter in a movement that’s already resonating with kids, collectors, and families around the world,” said Luca Netz, CEO of Pudgy Penguins.

Pudgy Penguins and Random House to Publish First Children’s Book
Source: Pudgy Penguins

What does this mean for Pudgy Penguins?

This book marks the first publishing collaboration for Pudgy Penguins, originally launched in 2021 as a collection of Ethereum-based NFTs. Since then, the brand has expanded into physical toys, gaming, and social media content, and has built a significant following on platforms such as TikTok and Instagram.

By entering the children’s book market, Pudgy Penguins is moving further into mainstream consumer media. The brand has previously placed toy products in major US retailers including Walmart, Target, and Walgreens, reporting over one million units sold and more than $13 million in retail revenue.

“Random House Children’s Books is the gold standard in publishing,” said Luca Netz. “They understand the power of narrative and building lasting characters. As the leading web3 brand bringing digital culture into the mainstream, this collaboration marks a major milestone in our continued expansion.”

The collaboration with Penguin Random House suggests Pudgy Penguins is pursuing a multi-platform strategy that includes retail, publishing, and digital engagement. Future projects have not been announced but are expected to follow in a similar direction.

]]>
https://earlybirdsinvest.com/pudgy-penguins-and-random-house-to-publish-first-childrens-book/feed/ 0 37520