Shai-Hulud npm supply chain attack – new compromised packages detected
jfrog.com | 事件 | #cloud | #supply-chain | #malware | #credential-theft | #npm | #jfrog | #shai-hulud
摘要
JFrog 披露 Shai-Hulud 攻击第二波:796 个新增恶意 npm 包,混淆与持久化升级;载荷窃取 GitHub、npm、AWS、GCP 凭证,并调用 TruffleHog 扩大窃密。
- 发布时间
- 收录时间
Skip to content