社会热点 None 周下载超 69 万次:热门 npm 包 node-ipc 被投毒,可窃取密码等敏感信息 IT之家 5 月 16 日消息,科技媒体 NeoWin 昨日(5 月 15 日)发布博文, 报道称 npm 热门包 node-ipc 遭遇新的供应链攻击,多个新发布版本被植入信息窃取恶意代码。IT之家注:node-ipc 是一个 Node。 node npm ipc 2026-05-16 IT之家
安全攻防 None Mini Shai-Hulud 蠕虫危害 TanStack、Mistral AI、Guardrails AI 及更多软件包 TeamPCP, the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and the been npm 2026-05-12 info@thehackernews.com (The Hacker News)
社会热点 None npm生态遭受大范围投毒:TanStack、Mistral AI、UiPath等受波及,可窃取云密钥与GitHub令牌 IT之家 5 月 12 日消息,网络安全检测机构 Socket 于当地时间 5 月 11 日发出警报,在开源工具库 TanStack 旗下约 84 个 NPM 软件包的恶意版本中发现疑似凭证窃取恶意代码。 npm squawk opensearch 2026-05-12 IT之家
开发者生态 None 攻击者在Flippa上购买了30个WordPress插件,并在所有插件中植入了后门 一名攻击者在数字市场Flippa上以六位数的价格购入了Essential Plugin的全部产品组合,其中包括30多个WordPress插件,总安装量达40万次。该买家的 首次代码提交 "便是一个PHP反序列化后门。该后门潜伏了八个月,直至 WordPress npm php 2026-05-12 作者:Steef-Jan Wiggers
开发者生态 None Show HN:安全安装 – 具有可信构建依赖项的更安全的 NPM 安装 In light of the ongoing npm supply chain compromises, I built safe-install: https://www。com/package/@gkiely/safe-install install https com 2026-05-12 gkiely
开发者生态 None 事后分析:TanStack npm 供应链妥协 Start RC Start RC Router Router Query Query Table Table DB beta DB beta AI alpha AI alpha Form new Form new Virtual Virt alpha the npm 2026-05-12 varunsharma07
开发者生态 None TanStack NPM 软件包受到威胁 TanStack / router Public Uh oh。There was an error while loading。Please reload this page。Notifications You must be signed are npm Copy 2026-05-11 varunsharma07