新型Shai-Hulud恶意软件浪潮感染600个NPM包
一场名为Shai-Hulud的新型恶意软件攻击浪潮已感染超过600个NPM软件包,对JavaScript生态系统构成严重威胁。攻击者通过依赖混淆和包名仿冒等技术进行投毒,受感染的包可能被用于数据窃取和后门植入。开发者和企业需立即审查项目依赖,并加强供应链安全防护措施。
一场名为Shai-Hulud的新型恶意软件攻击浪潮已感染超过600个NPM软件包,对JavaScript生态系统构成严重威胁。攻击者通过依赖混淆和包名仿冒等技术进行投毒,受感染的包可能被用于数据窃取和后门植入。开发者和企业需立即审查项目依赖,并加强供应链安全防护措施。
Patrick McKenzie notes that an LLM-produced blog post analyzing supply chain attack clusters, published by msuiche, is the first AI-generated public artifact he finds professionally relevant and complete enough that the lack of a human author does not materially compromise its utility.
A user reports receiving an Amber Alert from the California Highway Patrol containing a bit.ly link that redirected to a spammy 3gp file converter site, not legitimate information. Despite the suspicious link, the alert was real and matched a listing on missingkids.com. The issue was likely a copy-paste error, as a corrected alert was sent 39 minutes later.
The Bhutanese government, through its Computer Incident Response Team (BtCIRT), has joined Have I Been Pwned's free government service as the 45th government onboarded. BtCIRT now monitors Bhutanese government domains against the data in HIBP.
exe.dev is a cloud service designed for the agent era, offering pools of VMs with SSH, root access, and web authentication by default. It injects secrets at the network edge to keep them out of LLM hands, and supports persistent servers, internal tools, vibe coding, and disposable devboxes.