头条
3 家媒体·3 篇报道

Shai-Hulud npm 蜜罐程序并未伪造安全检查——它确实获得了合法验证

被称为 ChainDrop 的蠕虫,基于 Shai-Hulud 代码,已渗透超过 1,300 个 npm 包,其中包括知名模块 Keyv、Cacheable 和 flat-cache。该恶意软件伪装成合法包,顺利通过安全检查并显得可信,从而在 npm 生态系统中广泛传播。

本文综合以下全部报道写成,而非依据任何单一来源。

本页由机器翻译生成,原始报道为其原文语言。

各家媒体如何报道

  1. TechMeme·
    Researchers: ChainDrop, a Shai-Hulud-based worm, has compromised 1,300+ npm packages, like Keyv, Cacheable, and flat-cache, with a combined 2B monthly downloads (Bill Toulas/BleepingComputer)
  2. The Next Web·
    A worm tore through npm by making the malware look perfectly legitimate
  3. VentureBeat·
    The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one