扫码下载
BTC $70,496.12 +0.10%
ETH $2,155.32 +0.92%
BNB $639.17 +1.02%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $477.61 +1.26%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9495 +0.86%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%
BTC $70,496.12 +0.10%
ETH $2,155.32 +0.92%
BNB $639.17 +1.02%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $477.61 +1.26%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9495 +0.86%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%

针对 NPM 供应链的攻击事件再次发生

2025-09-16 09:31:56
收藏

ChainCatcher 消息,Scam Sniffer 监测到又一起针对 NPM 供应链的攻击事件,@ctrl/tinycolor(每周下载量达 220 万次)发布了恶意版本,该版本会在 npm 执行 postinstall(安装后)脚本时运行信息窃取程序,以扫描并窃取敏感数据。

此恶意载荷滥用了合法的敏感信息扫描工具 TruffleHog。请检查是否下载了受影响的版本,暂停安装/更新操作,并将版本固定为已知安全的版本。

app_icon
ChainCatcher 与创新者共建Web3世界