注册并分享邀请链接,可获得视频播放与邀请奖励。

Socket (@SocketSecurity) “🚨 The popular PyPI package lightning has been compromised in a supply chain att” — TopicDigg

Socket 的个人资料封面
Socket 的头像
Socket
@SocketSecurity
Socket is the #1# software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware
加入 November 2021
4.6K 正在关注    15.4K 粉丝
🚨 The popular PyPI package lightning has been compromised in a supply chain attack. Socket detected malicious code in versions 2.6.2 and 2.6.3 that executes automatically on import, downloads Bun, and runs an 11 MB obfuscated JavaScript payload designed to steal credentials. This appears to be connected to yesterday's mini Shai-Hulud attack, but we're still investigating. #Python#
显示更多
0
7
346
96
转发到社区