코인 매입
시장
현물
선물
재테크
이벤트
더 알아보기
reward-center초보자 존
홈 피드빠른 소식 정보
Security Alert: Red Hat Cloud Service npm Package Endures Supply Chain Attack, Stolen Credentials Found in Over 300 GitHub Repositories
  • CLOUD0%

BlockBeats News, June 2, SlowMist released a security alert, detecting an ongoing npm supply chain attack targeting the @redhat-cloud-services related packages. Currently, 31+ affected packages have been confirmed, with a weekly download volume of approximately 11.6k times, and over 300 GitHub repositories have compromised credentials. The attack method is highly similar to the previous "Shai-Hulud" npm attack, involving credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still active, and developers are still being continuously infected.

Potential threats include: GitHub/npm token theft, AWS/GCP/Azure cloud credential exposure, SSH key and Kubernetes secret collection, leakage of local environment and wallet data, creation of malicious repositories, and persistent operations, and even potentially destructive behaviors after token revocation. It is recommended to immediately remove or downgrade the affected @redhat-cloud-services package versions, thoroughly audit CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, rebuild exposed developer machines or Runners from clean images, and remain highly vigilant.

출처:BlockBeats

면책 조항: 현재 콘텐츠는 제3자 관점에서 제공되거나 제3자 관점에서 AI가 직접 번역한 것입니다. CoinEx는 콘텐츠의 진위성, 정확성, 독창성을 보장하지 않으며 CoinEx의 투자 조언으로 간주하지 않습니다. 암호화폐 가격은 변동성이 크므로 잠재적인 위험에 유의하시기 바랍니다.

인기 검색
  • 코인
    가격
    24시간 변동