3 وسائل إعلام·4 تقارير
احمِ مؤسستك الآن من دودة شاي-هولود وخلل npm بخمس خطوات عملية
تم اختراق عدة حزم npm مستخدمة في مجموعة تطوير الويب TanStack في هجوم سلسلة التوريد المعروف بحدث Mini Shai-Hulud. كما تأثرت حزم Mistral المرتبطة، مما عرض المستخدمين لشفرة خبيثة أثناء التثبيت. يُظهر هذا الاختراق ثغرات في نظام npm والحاجة إلى التحقق الصارم من الاعتمادات.
كُتب هذا الملخص من كل التقارير أدناه، لا من تقرير واحد.
ترجمة آلية. التقارير الأصلية بلغتها الأصلية.
كيف جرى تناوله
- Hacker News·Postmortem: TanStack npm supply-chain compromise
- TechMeme·Several npm packages for the TanStack web development tools were compromised in the Mini Shai-Hulud supply chain attack; Mistral packages were also affected (Socket)
- Hacker News·Show HN: Safe-install – safer NPM installs with trusted build dependencies
- VentureBeat·Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps