PulseAugur
中
实时 04:17:27
English(EN) Keyv and friends compromised in active Shai-Hulud supply chain attack

供应链攻击感染 868 个 npm 包,窃取凭证蠕虫

2026年8月4日,攻击者攻破了流行的 npm 包 'keyv' 及其相关库维护者的 GitHub 账户。这使得他们能够将窃取凭证的蠕虫注入到至少 868 个软件包中,影响了超过 20 亿次的月度安装量。恶意代码伪装成 'setup.mjs' 执行了一个窃取 npm、GitHub 和 AWS 凭证的有效载荷,并试图传播到其他软件包。 AI

影响 被攻破的软件包可能会影响 AI 开发工具和基础设施,可能导致数据泄露或中断。

排序理由 影响广泛使用的软件软件包的供应链攻击。

在 Hacker News — AI stories ≥50 points 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

供应链攻击感染 868 个 npm 包,窃取凭证蠕虫

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
影响广泛使用的软件软件包的供应链攻击。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
64 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. Hacker News — AI stories ≥50 points TIER_1 English(EN) · cimi_ ·

    Keyv及其相关组件在活跃的Shai-Hulud供应链攻击中被攻破