首页 时政热点 科技头条 智能AI 安全攻防 数码硬件 开发者生态 汽车 游戏 社会热点 开源推荐 医疗健康 归档 标签 关于

被劫持的npm和Go包使用VS Code任务部署Python Infostealer

摘要

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS

npm packages and Cybersecurity researchers
2026-06-29 1 阅读 约1分钟阅读 info@thehackernews.com (The Hacker News)
分享:
字号:
网络安全研究人员发现了两个被劫持的 npm 软件包和一组 Go 软件包,这些软件包旨在在受感染的 Windows、Linux 和 macOS 主机上部署基于 Python 的信息窃取程序。 JFrog 在一份声明中表示:“这种攻击通过生命周期脚本避免了最常见的 npm 执行路径,可能是为了与 npm v12 的安全强化保持‘兼容’。”
这篇文章对您有帮助吗?

订阅66必读

每日精选科技资讯,直达你的邮箱