注册并分享邀请链接,可获得视频播放与邀请奖励。

galenyuan.eth (@galenyuan) “锁依赖版本!锁依赖版本!锁依赖版本!” — TopicDigg

galenyuan.eth 的个人资料封面
galenyuan.eth 的头像
galenyuan.eth
@galenyuan
Building @Rabby_io & @DeBankDeFi丨 Husband of @Daaaaaameng
加入 September 2014
1.4K 正在关注    2.4K 粉丝
锁依赖版本!锁依赖版本!锁依赖版本!
🚨 SlowMist TI Alert 🚨 A new Shai-Hulud / Miasma / Hades npm malware variant linked to the compromised npm developer account czirker, affecting the npm ecosystem. The campaign uses a preconfigured binding.gyp file to execute during npm install; reported scope includes 23 affected packages, with leo-logger noted at 3,140 weekly npm downloads. As of the tweet publication time, 408 infected GitHub repositories containing stolen credentials had already been observed. Potential attacker actions include GitHub token theft, npm token theft, AWS / GCP / Azure credential theft, local environment data exfiltration, malicious GitHub workflow abuse, and further npm supply-chain propagation. Security teams should immediately check lockfiles and package histories for affected versions, downgrade or remove impacted packages, rotate npm, GitHub, cloud, CI/CD, and application secrets, enforce 2FA. Thanks to @OX__Security for the excellent analysis. As always, stay vigilant! The following URL can be used to track the latest situation:
显示更多