供应链攻击瞄准 SAP npm 包,投递凭证窃取恶意软件
wiz.io | 博客 | #cloud | #supply-chain | #kubernetes | #malware | #credential-theft | #npm | #sap | #teampcp
摘要
TeamPCP 的「Mini Shai Hulud」行动:以 preinstall 脚本投毒 SAP 相关 npm 包,后波及 intercom-client 与 lightning;载荷窃取 Kubernetes、Vault 与云凭证,并借 zero.masscan.cloud 动态外联、GitHub 作后备信道。
- 发布时间
- 收录时间
Skip to content