注册并分享邀请链接,可获得视频播放与邀请奖励。

International Cyber Digest (@IntCyberDigest) “‼️ BREAKING: An active npm supply chain attack has compromised at least 868 pack” — TopicDigg

International Cyber Digest 的个人资料封面
International Cyber Digest 的头像
International Cyber Digest
@IntCyberDigest
加入 September 2024
0 正在关注    0 粉丝
‼️ BREAKING: An active npm supply chain attack has compromised at least 868 packages carrying over 2 billion monthly installs with a credential-stealing worm. Shai-Hulud is back. It started with the compromise of the GitHub account of the maintainer behind keyv, a library with roughly 127 million weekly npm downloads. A preinstall hook fires on npm install and drops a stealer that sweeps npm, GitHub, AWS, Kubernetes and Vault secrets, and then spreads to more maintainers.
显示更多
0
139
3.6K
502
转发到社区