官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

诈骗模式

Compromised package maintainers

An attacker publishes a malicious version through a legitimate package account.

Reference note · Sources below

研究文章和参考条目以英语发布。导航提供七种语言。

本文目录
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

An attacker publishes a malicious version through a legitimate package account.

Why it matters

Normal publisher reputation and automated upgrades spread the payload.

What to check

Require signed, reproducible builds and record exact version and publication time.

Sources

相关阅读

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包