๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

JFrog Security
@JFrogSecurity
The JFrog Security Research Team empowers developers and companies to excel by identifying, prioritizing, and mitigating software risks.
๊ฐ€์ž… November 2017
302 ํŒ”๋กœ์ž‰ ์ค‘    4.9K ํŒฌ
๐ŸšจSupply Chain SECURITY ALERT: "niagA oG eW ereH :duluH-iahS" ๐Ÿ”„ The Shai-Hulud supply chain attack has slithered into the @antv ecosystem, affecting more than 600 package releases . A compromised maintainer account was used to inject credential-stealing code into popular visualization and React packages (including echarts-for-react), threatening millions of weekly downloads. JFrog Curation customers using an Immaturity policy were fully protected from this attack, as all of the hijacked packages were flagged in less than 24 hours. See our blog for a full analysis of this attack, including an ongoing list of compromised packages (link shared soon in this thread).
๋” ๋ณด๊ธฐ