官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

诈骗模式

Poisoned software dependencies

A familiar or mistyped package adds key theft or transaction manipulation to a build.

Reference note · Sources below

研究文章和参考条目以英语发布。导航提供七种语言。

人物与项目

本文目录
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A familiar or mistyped package adds key theft or transaction manipulation to a build.

Why it matters

Users are reached through a developer's supply chain.

What to check

Pin versions, inspect lockfile changes and preserve package hashes and provenance.

Sources

相关阅读

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包