註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

JFrog Security
@JFrogSecurity
The JFrog Security Research Team empowers developers and companies to excel by identifying, prioritizing, and mitigating software risks.
加入 November 2017
302 正在關注    4.9K 粉絲
🚨Supply Chain SECURITY ALERT: "niagA oG eW ereH :duluH-iahS" 🔄 The Shai-Hulud supply chain attack has slithered into the @antv ecosystem, affecting more than 600 package releases . A compromised maintainer account was used to inject credential-stealing code into popular visualization and React packages (including echarts-for-react), threatening millions of weekly downloads. JFrog Curation customers using an Immaturity policy were fully protected from this attack, as all of the hijacked packages were flagged in less than 24 hours. See our blog for a full analysis of this attack, including an ongoing list of compromised packages (link shared soon in this thread).
顯示更多
0
5
87
19
轉發到社區