Binance Square
#npm

npm

Просмотров: 20,408
35 обсуждают
Block Cycle Hunter
·
--
慢雾最新警报:npm 供应链遭遇大规模入侵⚠️ Keyv/Cacheable 生态系统中招,攻击者已发布超过 2000 个恶意软件包版本,其中 keyv@6.0.0 已确认被植入后门。Keyv 作为一款支持 Redis、SQLite、PostgreSQL、MongoDB 等多后端的键值存储抽象库,每周下载量高达约 1.27 亿次,波及面相当广。 攻击手法与此前 Shai-Hulud npm 蠕虫病毒活动高度相似,高度自动化、可大规模复制。主要风险包括: 🔴 凭证窃取与环境变量泄露 🔴 CI/CD 密钥被破坏 🔴 远程恶意载荷投放 🔴 通过受感染开发环境横向传播 安全建议: 1️⃣ 立即识别并移除受影响软件包版本 2️⃣ 升级至已验证的安全版本 3️⃣ 全面审查依赖锁定文件与构建日志 4️⃣ 监控可疑出站连接 5️⃣ 轮换所有可能已暴露的凭据 供应链攻击往往在悄无声息中渗透开发链路,建议所有团队尤其是 Web3 项目方即刻开展自查,切勿掉以轻心。 #供应链安全 #npm #网络安全
慢雾最新警报:npm 供应链遭遇大规模入侵⚠️

Keyv/Cacheable 生态系统中招,攻击者已发布超过 2000 个恶意软件包版本,其中 keyv@6.0.0 已确认被植入后门。Keyv 作为一款支持 Redis、SQLite、PostgreSQL、MongoDB 等多后端的键值存储抽象库,每周下载量高达约 1.27 亿次,波及面相当广。

攻击手法与此前 Shai-Hulud npm 蠕虫病毒活动高度相似,高度自动化、可大规模复制。主要风险包括:

🔴 凭证窃取与环境变量泄露
🔴 CI/CD 密钥被破坏
🔴 远程恶意载荷投放
🔴 通过受感染开发环境横向传播

安全建议:
1️⃣ 立即识别并移除受影响软件包版本
2️⃣ 升级至已验证的安全版本
3️⃣ 全面审查依赖锁定文件与构建日志
4️⃣ 监控可疑出站连接
5️⃣ 轮换所有可能已暴露的凭据

供应链攻击往往在悄无声息中渗透开发链路,建议所有团队尤其是 Web3 项目方即刻开展自查,切勿掉以轻心。

#供应链安全 #npm #网络安全
慢雾安全团队刚刚监测到一起严重的恶意npm供应链攻击活动,正在针对npm用户和DeFi开发者发起攻击⚠️ 根据慢雾MistEye的检测,这是一起协调性的攻击,攻击者通过创建虚假的交易机器人代码库和DeFi主题的npm包,投放JavaScript信息窃取工具,目前已经发现了30个恶意npm包,其中包括stake-math@3.5.4。 特别值得注意的是,其中一个代码库donoaccestag/forex-mt5-trading-bot就依赖了这个恶意包,并且这个代码库已经产生了约2300个高度同质的分叉,大概率是攻击者批量生成的,主要集中在poly-stocks账户下。 一旦你的设备中招,攻击者可以窃取: 🔴 加密钱包私钥、助记词 🔴 浏览器cookies和保存的密码 🔴 开发者凭证、SSH密钥 🔴 shell历史、API令牌 🔴 密码管理器数据等敏感信息 **开发者需要立即做这些防护:** 1️⃣ 移除所有受影响的npm包 2️⃣ 审计package.json和package-lock.json以及CI日志 3️⃣ 凡是运行过npm install的系统都视为可能被攻击 4️⃣ 及时更换暴露的钱包密钥、npm令牌、云凭证等敏感信息 5️⃣ 从干净的镜像重建开发环境 安全无小事,供应链攻击近年来越来越频繁,所有DeFi开发者都需要提高警惕! #npm #慢雾 #供应链安全
慢雾安全团队刚刚监测到一起严重的恶意npm供应链攻击活动,正在针对npm用户和DeFi开发者发起攻击⚠️

根据慢雾MistEye的检测,这是一起协调性的攻击,攻击者通过创建虚假的交易机器人代码库和DeFi主题的npm包,投放JavaScript信息窃取工具,目前已经发现了30个恶意npm包,其中包括stake-math@3.5.4。

特别值得注意的是,其中一个代码库donoaccestag/forex-mt5-trading-bot就依赖了这个恶意包,并且这个代码库已经产生了约2300个高度同质的分叉,大概率是攻击者批量生成的,主要集中在poly-stocks账户下。

一旦你的设备中招,攻击者可以窃取:
🔴 加密钱包私钥、助记词
🔴 浏览器cookies和保存的密码
🔴 开发者凭证、SSH密钥
🔴 shell历史、API令牌
🔴 密码管理器数据等敏感信息

**开发者需要立即做这些防护:**
1️⃣ 移除所有受影响的npm包
2️⃣ 审计package.json和package-lock.json以及CI日志
3️⃣ 凡是运行过npm install的系统都视为可能被攻击
4️⃣ 及时更换暴露的钱包密钥、npm令牌、云凭证等敏感信息
5️⃣ 从干净的镜像重建开发环境

安全无小事,供应链攻击近年来越来越频繁,所有DeFi开发者都需要提高警惕!

#npm #慢雾 #供应链安全
🚨 安全警报:30个恶意npm包伪装成交易机器人,定向窃取开发者密钥与助记词! #npm #DeFi
🚨 安全警报:30个恶意npm包伪装成交易机器人,定向窃取开发者密钥与助记词! #npm #DeFi
慢雾安全团队刚刚发出警报,检测到一起针对 npm 用户和 DeFi 开发者的协调性恶意供应链攻击⚠️ 根据慢雾 MistEye 监测,攻击者通过虚假交易机器人代码库和 DeFi 主题的 npm 包,投放 JavaScript 信息窃取工具,目前已发现涉及 30 个恶意 npm 包,其中 stake-math@3.5.4 已经出现在公开代码库的锁定依赖项中。 更值得警惕的是,相关异常代码库已经产生了约 2300 个高度同质的分叉,大概率是攻击者批量生成,主要集中在 poly-stocks 账户下。 一旦中招,攻击者可以窃取你的: 🔴 加密钱包私钥、助记词 🔴 浏览器 cookies、保存的密码和浏览历史 🔴 开发者凭证、shell 历史、密码管理器数据 🔴 源代码中的 API 令牌等敏感信息 建议所有开发者立即采取行动: 1️⃣ 移除受影响的 npm 包 2️⃣ 审计 package.json / package-lock.json 和 CI 日志 3️⃣ 检查曾运行 npm install 的系统,及时更换暴露的密钥和凭证 4️⃣ 从干净镜像重建受影响环境 供应链攻击早已不是新鲜事,但针对加密开发者的定向攻击愈发频繁,大家一定要提高安全意识,及时检查依赖项❗️ #npm #供应链安全 #DeFi安全
慢雾安全团队刚刚发出警报,检测到一起针对 npm 用户和 DeFi 开发者的协调性恶意供应链攻击⚠️

根据慢雾 MistEye 监测,攻击者通过虚假交易机器人代码库和 DeFi 主题的 npm 包,投放 JavaScript 信息窃取工具,目前已发现涉及 30 个恶意 npm 包,其中 stake-math@3.5.4 已经出现在公开代码库的锁定依赖项中。

更值得警惕的是,相关异常代码库已经产生了约 2300 个高度同质的分叉,大概率是攻击者批量生成,主要集中在 poly-stocks 账户下。

一旦中招,攻击者可以窃取你的:
🔴 加密钱包私钥、助记词
🔴 浏览器 cookies、保存的密码和浏览历史
🔴 开发者凭证、shell 历史、密码管理器数据
🔴 源代码中的 API 令牌等敏感信息

建议所有开发者立即采取行动:
1️⃣ 移除受影响的 npm 包
2️⃣ 审计 package.json / package-lock.json 和 CI 日志
3️⃣ 检查曾运行 npm install 的系统,及时更换暴露的密钥和凭证
4️⃣ 从干净镜像重建受影响环境

供应链攻击早已不是新鲜事,但针对加密开发者的定向攻击愈发频繁,大家一定要提高安全意识,及时检查依赖项❗️

#npm #供应链安全 #DeFi安全
🚨 2,000 POISONED PACKAGES FLOOD $KEYV — 127M DOWNLOADS IN THE BLAST RADIUS! 💥 At 127M downloads a week, this isn't a bug — it's a weaponized breach with a huge blast radius. 🦈 The attacker flooded the Keyv/Cacheable ecosystem with 2,000+ malicious versions, including keyv@6.0.0, mirroring the Shai-Hulud worm's automation. 🔍 This is how projects get gutted from the inside: credential theft, CI/CD key leaks, remote payloads, lateral movement through dev environments. Every downstream app touching this library is exposed. 📊 If you hold keys or run build pipelines on Node.js, treat your dependencies as compromised until audited. Rotate credentials and inspect lock files now. ⚠️ 💬 Is your project's dependency tree clean, or are you one package away from a nightmare? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #KEYV #SupplyChainAttack #CryptoSecurity #CyberAlert #NPM 🔍 🛡️
🚨 2,000 POISONED PACKAGES FLOOD $KEYV — 127M DOWNLOADS IN THE BLAST RADIUS! 💥

At 127M downloads a week, this isn't a bug — it's a weaponized breach with a huge blast radius. 🦈 The attacker flooded the Keyv/Cacheable ecosystem with 2,000+ malicious versions, including keyv@6.0.0, mirroring the Shai-Hulud worm's automation. 🔍

This is how projects get gutted from the inside: credential theft, CI/CD key leaks, remote payloads, lateral movement through dev environments. Every downstream app touching this library is exposed. 📊

If you hold keys or run build pipelines on Node.js, treat your dependencies as compromised until audited. Rotate credentials and inspect lock files now. ⚠️ 💬 Is your project's dependency tree clean, or are you one package away from a nightmare? 👇

⚠️ Not financial advice. Always manage your risk. 🛡️

🏷️ #KEYV #SupplyChainAttack #CryptoSecurity #CyberAlert #NPM

🔍 🛡️
⚠️ هجوم برمجيات خبيثة يستهدف Vite عبر حزم npm ضارة اكتشف باحثو الأمن السيبراني سبع حزم npm خبيثة تستهدف بيئة أدوات الواجهة الأمامية Vite في هجوم على سلسلة التوريد البرمجية. تستخدم هذه الحزم تقنية Blockchain C2 لتوصيل برمجيات RAT، مما يبرز المخاطر المتزايدة في منظومة تطوير البرمجيات. ━━━━━━━━━━━━━━ 📊 التأثير: 📈 مرتفع 🏷️ OTHER #Cybersecurity #SupplyChainAttack #npm #Vite #Malware 🔗 المصدر: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
⚠️ هجوم برمجيات خبيثة يستهدف Vite عبر حزم npm ضارة

اكتشف باحثو الأمن السيبراني سبع حزم npm خبيثة تستهدف بيئة أدوات الواجهة الأمامية Vite في هجوم على سلسلة التوريد البرمجية. تستخدم هذه الحزم تقنية Blockchain C2 لتوصيل برمجيات RAT، مما يبرز المخاطر المتزايدة في منظومة تطوير البرمجيات.

━━━━━━━━━━━━━━
📊 التأثير: 📈 مرتفع
🏷️ OTHER

#Cybersecurity #SupplyChainAttack #npm #Vite #Malware

🔗 المصدر: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
🚨 Security alert: Hackers attempted to backdoor an Injective npm package to steal wallet keys. Supply-chain attacks are now targeting the crypto developer stack directly. According to security firm Socket, malicious code was injected into an npm package tied to Injective's wallet workflows — designed to silently siphon private keys and credentials from developers and the apps they build. Why it matters: • npm packages sit at the core of most Web3 front-ends and tooling • A single compromised dependency can drain countless user wallets • The incident hits Injective, a Cosmos-based L1 popular for DeFi and on-chain trading Socket researchers warned the risk is especially severe for apps that handle Injective wallet connections, where a tainted package could exfiltrate keys at the moment users sign in. The good news: the package was flagged before widespread adoption. But it's a stark reminder that "just npm install" is no longer safe in crypto. Teams should pin dependencies, audit lockfiles, and use scanner tools to catch suspicious post-install scripts. As more value moves on-chain, the attack surface shifts to the code itself. Stay paranoid, devs. 🔐 #Injective #CryptoSecurity #DeFi #Web3 #npm
🚨 Security alert: Hackers attempted to backdoor an Injective npm package to steal wallet keys.

Supply-chain attacks are now targeting the crypto developer stack directly. According to security firm Socket, malicious code was injected into an npm package tied to Injective's wallet workflows — designed to silently siphon private keys and credentials from developers and the apps they build.

Why it matters:
• npm packages sit at the core of most Web3 front-ends and tooling
• A single compromised dependency can drain countless user wallets
• The incident hits Injective, a Cosmos-based L1 popular for DeFi and on-chain trading

Socket researchers warned the risk is especially severe for apps that handle Injective wallet connections, where a tainted package could exfiltrate keys at the moment users sign in.

The good news: the package was flagged before widespread adoption. But it's a stark reminder that "just npm install" is no longer safe in crypto. Teams should pin dependencies, audit lockfiles, and use scanner tools to catch suspicious post-install scripts.

As more value moves on-chain, the attack surface shifts to the code itself. Stay paranoid, devs. 🔐

#Injective #CryptoSecurity #DeFi #Web3 #npm
Войдите, чтобы посмотреть больше материала
Присоединяйтесь к пользователям криптовалют по всему миру на Binance Square
⚡️ Получайте новейшую и полезную информацию о криптоактивах.
💬 Нам доверяет крупнейшая в мире криптобиржа.
👍 Получите достоверные аналитические данные от верифицированных создателей контента.
Эл. почта/номер телефона