⚠️ A new wave of the Mini Shai-Hulud, Miasma & Hades supply chain attack is spreading through 23 malicious PyPI packages aimed at bioinformatics and MCP/AI developers.
If you install one, it silently drops a credential stealer on your machine and CI/CD pipeline, then hunts for your secrets.
What it steals:
→ GitHub, npm, PyPI, and JFrog tokens
→ Cloud and Kubernetes credentials
→ SSH keys, Docker configs, and .env files
Why it's dangerous: the malicious code hides three different ways (startup hooks, trojanized native extensions, and a loader that pulls its payload from elsewhere), so reviewing the Python source alone won't catch it. It even includes a decoy comment designed to fool AI security scanners.
Watch out for these (compromised real packages, typosquats, and lookalike bait):
→ embiggen, ensmallen, pyphetools
→ rsquests, tlask, rlask
→ fake LangChain/OpenAI/MCP packages
What to do now: audit your environments for these packages, remove anything affected, and rotate any tokens that may have been exposed.
Full breakdown 👇
socket.dev/blog/mini-shai…
Awareness is the first line of defense. Deepfakes and voice cloning aren't a future problem. We see them weaponized in scams every single day. Glad to see this getting mainstream attention 👏
Conan O’Brien has partnered with cybersecurity AI firm Adaptive Security for a 15-part training series on spotting cyber threats emerging in the AI age.
The series will cover risks including deepfakes, voice cloning, impersonation, phishing and physical safety.
The cybersecurity team at my company sent out a fake phishing email to everyone advertising discounted FIFA tickets
A LOT of people clicked on the link and were assigned additional scam detection training 💀
LIGHTS IN DARK ROOMS. TRAILER DROPS IN 2 DAYS.
@MechelleBMoore, CEO of @GlobalAlmsInc, shared a wealth of knowledge from her experience combatting the harms of the scam compounds and showed us the reality up close. Her teams work continues to help recover and repatriate victims who were trafficked into Myanmar.
60% of all documentary donations go directly to 🙏 globalalms.comgiveth.io/project/lights…
🚨 Gaming brands get cloned, faked, and impersonated every single day.
Fake sportsbook sites and impersonator accounts target operators and their players around the clock, offering bogus bonuses and phishing for logins under your brand's name. ChainPatrol detects them and gets them taken down fast, often within minutes, across domains, X, Telegram, Meta, and more.
This week, @ConorOrlando7 is on the ground in Fort Lauderdale for @SBCGAMINGNEWS' SBC Summit (June 9 to 11).
Come find us on the floor 👋 or book a demo: chainpatrol.com/demo
🛡️ Counterfeit sites and fake brand accounts don't take a day off. For retailers, every cloned storefront is a customer one click away from a scam.
That's what we're at @shoptalk Europe 2026 to talk about this week. ChainPatrol finds the fake domains, impersonator accounts, and copycat storefronts targeting brands and their customers, then gets them taken down fast across domains, social platforms, and marketplaces.
The ChainPatrol team is on the floor in Barcelona for the next few days. If brand protection is on your radar, come say hi 👋
🚨 Scams are now a trillion-dollar global industry. This is the room fighting back.
We are in Lisbon this week for the @ScamAlliance Summit Europe (June 9–10), alongside the people on the front lines of stopping fraud. Detecting impersonation and shutting down scams before they reach people is the whole reason ChainPatrol exists.
If you're attending, see you there 👋
Our CTO and Co-Founder @umariomaker is in Montreal June 8–11 for @M3AAWG, working with the anti-abuse community to shut down phishing, malware, and messaging abuse at the source.
Come say hi 👋
LIGHTS IN DARK ROOMS. TRAILER DROPS IN 3 DAYS.
Today we highlight @dobsec. Security researcher, collaborator, and one of the folks whose work inspired us to make Lights in Dark Rooms.
His insight in the documentary is a reflection of his continued efforts to bring awareness to this global problem of industrialized scam operations.
LIGHTS IN DARK ROOMS. TRAILER DROPS IN 4 DAYS.
📍 Manila, Philippines. We visited multiple office towers in which scam centres were known to have been operating. We spoke to Winston Casio who previously served as Director of PAOCC, an anti-organized crime team, and lead the investigative efforts that took down many of these scam operations in the Philippines.
His chapter in Lights in Dark Rooms is one of the most powerful in the film.
#LightsInDarkRooms#Manila#Documentary
LIGHTS IN DARK ROOMS. TRAILER DROPS IN 5 DAYS.
They lived it. They survived it.
Speaking with survivors of scam compound captivity was the most profound part of making Lights in Dark Rooms. Their voices carry the weight of this crisis in a way no statistic ever could.
Understanding the role of the mempool is essential for grasping how transactions are processed and protected on-chain. @bezzenberger explains that the mempool serves as a public waiting area where transactions float through a peer-to-peer network before being included in a block. This transparency allows validators to see pending activity and potentially exploit it through sandwich attacks—front-running a user's trade to buy cheap and then selling back to them at a higher price. By highlighting these vulnerabilities, we can better understand the need for infrastructure that secures users against predatory ordering.
Clip from Hot Takes & Cold Wallets with Umar, @JuanAriel98 and @wiimee, featuring special guest @bezzenberger.
Watch the full episode here: x.com/i/broadcasts/1k
That's a wrap on @money2020 Europe! 💸
A lot of great energy on the floor and excitement for the future of brand protection
Huge thanks to everyone we connected with in Amsterdam. Until next time! 👋
#M2020Eu
Hot Takes and Cold Wallets : Episode 25🎙️
We talk about the recent Meta chatbot account reset incident, having a plan for compromised accounts and our approach to Web2 brand security.
Timestamps:
0:00 Inro
1:17 ChainPatrol Update - 5K Followers on X!
4:15 Pitching ChainPatrol to Web2 Brands
5:46 Account Code Resets via Meta Chatbot
12:43 Having a Plan for Compromised Accounts
17:24 Gnosis Pay Incident
23:22 Lessons for Crypto Card Users
28:25 Trezor secure chip hack
34:15 Countdown to “Lights in Dark Rooms” Documentary Trailertary Trailer
Catch us live every Thursday at 3pm ET!
LIGHTS IN DARK ROOMS. TRAILER DROPS IN 6 DAYS.
Before ➡️ After. Same place.
What was once open, empty land is now a scam compound stretching across the landscape. Swipe through and see the scale for yourself.
This is why Lights in Dark Rooms exists.
Proudly protecting @fastxyz 🤝
In the fast-moving world of AI agents and crypto payments, trust and security are critical. By actively monitoring to find and takedown scams, fake account and impersonators — We help keep the ecosystem safe so builders and agents can operate with confidence.
That's a wrap on the @Gartner_inc Security & Risk Management Summit 🤝
Thanks to everyone who stopped by to talk threat detection and takedowns.
#GartnerSEC
Proudly protecting @fastxyz 🤝
In the fast-moving world of AI agents and crypto payments, trust and security are critical. By actively monitoring to find and takedown scams, fake account and impersonators — We help keep the ecosystem safe so builders and agents can operate with
LIGHTS IN DARK ROOMS. TRAILER DROPS IN 8 DAYS.
Here is a look at our experience driving through scam compound territory along the border with Myanmar. We were able to observe activity within the compounds from a distance by mounting our camera to a telescope!
Thank you to @MechelleBMoore for sharing your knowledge with us so that we can help spread the message.
We'll be sharing what we captured here as part of the trailer release countdown.
21 Followers 933 Following$XRP & $FLR OG • Investor since 2018 • Self-made from 0 with no handouts • Marketing Expert • Delegate your $FLR → @PriceKraken 💰
25K Followers 10K FollowingWe verify your existing casino play to unlock FREE suites at 85 luxury casino resorts and 14 cruises lines almost anywhere you want to go. Qualify Below
34K Followers 28K FollowingWe verify your existing casino play to unlock FREE suites at 85 luxury casino resorts and 14 cruises lines almost anywhere you want to go. Qualify Below
491 Followers 1K FollowingXYZ Verse is here to dominate the memecoin game. The first all-sports memecoin is right here!
Join the official XYZVerse Telegram channel: https://t.co/lTudgjGDcH
43K Followers 9K FollowingWe verify your existing casino play to unlock FREE suites at 85 luxury casino resorts and 14 cruises lines almost anywhere you want to go. Qualify Below👇🏻
11K Followers 11K FollowingWe verify your existing casino play to unlock FREE suites at 85 luxury casino resorts and 14 cruises lines almost anywhere you want to go. Qualify Below
114 Followers 822 FollowingSeasoned Crowdfunding expert with years of experience
Expert in campaign creation, pitch writing, banner design, video creation & donor email lists
72 Followers 2K FollowingCNBC Crypto Trader, Founder Crypto Banter.
Invest in protocols that will change the world-give them enough time to do their thing. Tweets not financial advice.
309 Followers 7K FollowingCNBC Crypto Trader, Founder Crypto Banter. Invest in protocols that will change the world-give them enough time to do their thing. Tweets not financial advice…
435 Followers 2K FollowingNext generation of on-chain asset management and market intelligence.
Market intelligence and arbitrage screener at https://t.co/7waZXLoNLy
111 Followers 2K FollowingMaking On-Chain Transactions Simple & Gas Free | Leveraged by Native AA and Intents | 3M transactions and 250K users | @ZyFAI
90 Followers 690 FollowingThe ultimate 2025 crypto wallet. POSTS NOT INTENDED FOR UK USERS Best Wallet Support: https://t.co/QwTaHJYiYn... https://t.co/hgzd1i5jVX
251 Followers 3K FollowingThe ultimate 2025 crypto wallet. POSTS NOT INTENDED FOR UK USERS Best Wallet Support: https://t.co/xpbLVVKpYK... https://t.co/69G8OIYKNk
3K Followers 2K Following💖 Events connecting & welcoming women in Web3
🔮 Part of @Futurist_Conf
🇨🇦 Part of @CanadaCryptoWk
💫 Next Event:
📍 July 21-22, 2026
📍 Toronto, Canada
464 Followers 6K FollowingCo-CEO @SharpLinkGaming (Nasdaq: SBET). Former Head of Digital Assets Strategy @BlackRock. Focused on Ethereum, tokenization and the future of finance.
675 Followers 8K FollowingShaping the future of blockchain with BlockDAG! 🔥BWT Alpine Formula One® Team's #officialblockchainpartner https://t.co/0m3hzfUr7b….
40K Followers 13 FollowingOnchain Everything Exchange, where you can build advanced strategies over any assets, spot/perp/pred mkts. Backed by @cbventures @Alliance
https://t.co/s4hvkuW8WA
46K Followers 1 FollowingAlternative asset management and technology firm that operates liquid and venture strategies focused on the digital asset ecosystem.
https://t.co/VTCozTZoPu
53K Followers 904 Following$XRP & $FLR OG • Investor since 2018 • Self-made from 0 with no handouts • Marketing Expert • Delegate your $FLR → @PriceKraken 💰
262K Followers 1K FollowingCEO @0G_labs & exec chairman @stack0g: making AI a public good | Forbes 40 under 40 | Ex-Bridgewater, Bain, MSFT, Garten (founded prev. top @ycombinator co)
9K Followers 345 Followinginvesting and building in crypto x AI | prev tech-lead @ instacart ads | data and infra @ coinbase, pagerduty, seatgeek etc | cs @ uwaterloo
221K Followers 43 FollowingWe will eat the fees 🍽️ No delivery or service fees on restaurant orders $50+. Details at https://t.co/OMLdz9nh4r
Need help with an order? @Grubhub_Care
87K Followers 2K FollowingGlobal crypto news media est. 2018 ¦ breaking news, analysis, podcasts & more.
Nominate your choice for BeInCrypto 100 Awards: https://t.co/esC6c9VahC
2K Followers 2K Followingearly stage investor @CastleIslandVC; BOD @felixpago @eaglebrook @cyclops_inc @officialxfx @valinordigital former BOD: @beam_cash (acq by Modern Treasury)
778 Followers 123 FollowingUnlock stablecoin yield in your wallet or DeFi app. Safe, automated, non-custodial. Built for stable growth. Built by @PaltaLabs 🥑
743K Followers 220 FollowingFollow for the latest Morgan Stanley news, expert insights and to see how our integrated firm supports clients globally. Disclosures: https://t.co/SyWvl5q9ac
897 Followers 260 FollowingSimplifying DeFi on @StellarOrg 💸
@SoroswapFinance: Best routes for your swaps
@DeFindex_: Plug & play DeFi for wallets
→ Explore more: https://t.co/JCN849C18z 🌐
1K Followers 87 FollowingAktionariat brings all the tools for tokenized equity into a single ecosystem from shareholder management and issuance to trading and compliance.
39K Followers 216 FollowingEnabling community-led growth, development & self-sustainability of the @dYdX protocol | Participate in governance at https://t.co/K4H8TFX5hi
72K Followers 3 FollowingCitrea is the Bitcoin's application layer, enabling institutions and users to access Bitcoin capital markets.
Mainnet is Live → https://t.co/prCRpathbk
40K Followers 66 FollowingEarn, Swap, and Borrow: All with maximum capital efficiency 🌊 | On Ethereum & EVM: Fluid | On Solana: @jup_lend | by @instadapp