SlowMist·May 11Threat Intelligence | Analysis of a Fake TronLink Chrome Extension Phishing CampaignBackground
SlowMist·Mar 26Security Alert: Supply Chain Attack on Apifox Desktop Client via Compromised Official CDN Script1. Background
SlowMist·Feb 9Threat Intelligence | Analysis of ClawHub Malicious Skills PoisoningAt its core, this incident stems from supply chain risks caused by “ecosystem entry points combined with executable text instructions.”
SlowMist·Feb 2Threat Intelligence | Analysis of Token Vesting Phishing PoisoningThis was a targeted attack against the macOS platform that combined social engineering techniques with multi-stage fileless payloads.
SlowMist·Nov 27, 2025Threat Intelligence | NPM Supply-Chain Poisoning Analysis — Reconstructing the Shai-Hulud AttackThis NPM poisoning used worms, self-hosted runners, and TruffleHog.
SlowMist·Nov 17, 2025Threat Intelligence: Analysis of the NOFX AI Automated Trading VulnerabilityAlthough the NOFX project has undergone attempted fixes, the core issue remains unresolved.
SlowMist·Jul 22, 2025Threat Intelligence: An Analysis of a Malicious Solana Open-source Trading BotThe project reads sensitive information from the local environment and uploads the private key to a hacker-controlled server.A response icon1A response icon1