๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Moshe Siman Tov Bustan
@MosheTov
Security Research Team Lead @OX__Security Guitars @CompileBand 23x CVEs 3x Conference Talks
๊ฐ€์ž… October 2013
485 ํŒ”๋กœ์ž‰ ์ค‘    868 ํŒฌ
๐Ÿšจ NPM Malware-slop Alert!๐Ÿšจ We detected and reported a malware-slop package to npm - the malware uses it's OWN PRIVATE GitHub token, which is EMBEDDED INSIDE the malware itself - to read sensitive information and upload it to the threat actor's GitHub repository. The malware is still live on npm - The threat actor's GitHub page was opened 5h ago - Detailed report will be published tomorrow.
๋” ๋ณด๊ธฐ