Keyv生态遭受大规模npm供应链攻击,超2000个恶意包版本被发布
2026-08-05 11:43:07
币界网消息,据慢雾监测,Keyv生态系统遭遇大规模npm供应链攻击,攻击者发布了超过2000个恶意包版本,包括keyv .0.0。Keyv是广泛使用的键值存储抽象库,支持redis、sqlite、postgresql、mongodb等后端,每周下载量约1.27亿次,导致明显的下游供应链暴露。攻击手法与shai-hulud npm蠕虫活动高度相似,指向高度自动化和可扩展的供应链攻击。潜在攻击行为包括凭据窃取、环境变量泄露、ci/cd密钥泄露、远程载荷投递及通过被入侵的开发环境横向传播。
出典:互联网
このコンテンツは市場情報のみを提供するものであり、投資アドバイスを構成するものではありません。
HQYC公式アカウントをフォローして最新情報を入手
人気記事
更新

Web3: Circle obtains New York trust license, expanding USDC custody business.
07-31 22:04

Tesla reportedly plans to divest its China business to pave the way for integration with SpaceX.
07-31 21:54

web3: Foreign media: RWA perpetual contracts may expand faster than tokenization
07-31 21:24

Web3: Foreign media: Analysts say the real catalyst for XRP is not the Clarity Act.
07-31 20:55

Foreign media: Trump's children's accounts are unlikely to replace comprehensive family financial planning
07-31 20:24

