📢 Exclusive on Gate Square — #PROVE Creative Contest# is Now Live!
CandyDrop × Succinct (PROVE) — Trade to share 200,000 PROVE 👉 https://www.gate.com/announcements/article/46469
Futures Lucky Draw Challenge: Guaranteed 1 PROVE Airdrop per User 👉 https://www.gate.com/announcements/article/46491
🎁 Endless creativity · Rewards keep coming — Post to share 300 PROVE!
📅 Event PeriodAugust 12, 2025, 04:00 – August 17, 2025, 16:00 UTC
📌 How to Participate
1.Publish original content on Gate Square related to PROVE or the above activities (minimum 100 words; any format: analysis, tutorial, creativ
Socket: Malicious npm packages targeting BSC and Ethereum users discovered, stealing encryption wallet assets.
According to Foresight News, the Socket threat research team released a report saying that it has found four malicious npm packages targeting BSC and Ethereum to steal users' crypto wallet assets. The four packages are: pancakeuniswapvalidatorsutilssnipe (350 downloads), pancakeswap-oracle-prediction (445 downloads), ethereum-smart-contract (305 downloads), and env-process (1054 downloads), with a total of over 2,100 downloads. The attacker uses obfuscated JavaScript code to steal 80%-85% of the target's wallet balance and go to an address they control. The packages were written by the same actor and spanned 3-4 years ago. Socket recommends that developers adopt automated dependency scanning and secure credential management to prevent attacks. Foresight News Note: npm packages refer to JavaScript packages that are managed through the npm (Node Package Manager). npm is Node.js's default package manager for installing, sharing, and managing JavaScript projects' dependencies and codebases.