
Welcome to Pump.fun!
Pump lets anyone create coins, giving everyone equal access to buy and sell from the start. Prices can move quickly, so trade carefully.
By clicking this button, you agree to the Terms and Conditions, Privacy Policy, and certify that you are over 18 years old.
$ATTACK
The attack began on August 4 when an intruder took over the GitHub account of the keyv maintainer and published a malicious 6.0.0 release. A preinstall hook in that version harvested npm tokens, GitHub credentials, and AWS keys, then spread to other packages including cacheable-request and file-entry-cache. Security teams tracked the spread in real time while npm rotated tokens and pushed a CLI upgrade. Developers are advised to pin clean versions, rotate credentials, and tighten dependency policies.