Logótipo oficial do MASTR MASTR Apoiar o trabalho
Índice
← Início da wiki

Tipos de fraude

Compromised package maintainers

An attacker publishes a malicious version through a legitimate package account.

Reference note · Sources below

Os artigos de investigação e as referências são publicados em inglês. A navegação está disponível em sete idiomas.

Neste artigo
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

An attacker publishes a malicious version through a legitimate package account.

Why it matters

Normal publisher reputation and automated upgrades spread the payload.

What to check

Require signed, reproducible builds and record exact version and publication time.

Sources

Leituras relacionadas

MASTR

Apoiar a investigação independente

As investigações, as provas originais e os guias são de acesso livre. Os donativos voluntários ajudam a financiar a investigação e a manter disponíveis as ferramentas MASTR.

Abrir carteira