3 家媒体·3 篇报道
Shai-Hulud npm 蜜罐程序并未伪造安全检查——它确实获得了合法验证
被称为 ChainDrop 的蠕虫,基于 Shai-Hulud 代码,已渗透超过 1,300 个 npm 包,其中包括知名模块 Keyv、Cacheable 和 flat-cache。该恶意软件伪装成合法包,顺利通过安全检查并显得可信,从而在 npm 生态系统中广泛传播。
本文综合以下全部报道写成,而非依据任何单一来源。
本页由机器翻译生成,原始报道为其原文语言。
各家媒体如何报道
- TechMeme·Researchers: ChainDrop, a Shai-Hulud-based worm, has compromised 1,300+ npm packages, like Keyv, Cacheable, and flat-cache, with a combined 2B monthly downloads (Bill Toulas/BleepingComputer)
- The Next Web·A worm tore through npm by making the malware look perfectly legitimate
- VentureBeat·The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one