PulseAugur
实时 08:31:18
English(EN) Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

Miasma 恶意软件污染 npm 包,目标是开发者秘密

一个被称为 Miasma 的复杂恶意软件活动已破坏了 20 多个 npm 包,通过窃取凭证来针对开发者,并寻求扩大其影响范围。此次攻击特别影响了 Leo PlatformRStreams 包,攻击者旨在获取更多维护者的账户访问权限。微软一直在追踪此次活动,凸显了对软件供应链日益增长的威胁。 AI

影响 此事件凸显了供应链攻击日益复杂化,对 AI 开发工具和基础设施构成风险。

排序理由 该集群描述了一次针对软件包注册表的恶意软件活动,属于工具和安全威胁类别。

在 The Register — AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

Miasma 恶意软件污染 npm 包,目标是开发者秘密

报道来源 [2]

  1. The Register — AI TIER_1 English(EN) ·

    Miasma 攻击污染 20 多个 npm 包,搜寻开发者秘密

    Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 Miasma活动感染20多个npm包,窃取开发者秘密 📝 Miasma恶意软件活动...

    🤖 Miasma campaign poisons 20-plus npm packages, hunts for developer secrets 📝 The Miasma malware campaign has ... https://www. theregister.com/security/2026/ 06/26/miasma-campaign-poisons-20-plus-npm-packages-hunts-for-developer-secrets/5262886 📰 www.theregister.com - Articles # …