官方的 MASTR 标志 MASTR
菜单
阅读文章

钓鱼攻击、漏洞与隐私

The JavaScript supply-chain worm: a warning for Web3 builders

The injected code auto-executes after install, pulls Trufflehog to hunt for secrets (tokens, API keys, passwords), then uses stolen maintainer creds to infect even more packages, a classic self-propagating supply-chain attack.

原文为英语,导航提供七种语言。

01

查看 X 原帖 ↗

🚨 JS Devs & Web3 Builders – Pay Attention! 🚨

A massive worm-style malware is ripping through the JavaScript ecosystem.

Nearly 500 compromised NPM package versions are confirmed.

It all started with @ctrl/tinycolor (2M+ weekly downloads!) and spread like wildfire.

Attack nicknamed “Shai-Hulud” – a Dune reference.

The injected code auto-executes after install, pulls Trufflehog to hunt for secrets (tokens, API keys, passwords), then uses stolen maintainer creds to infect even more packages, a classic self-propagating supply-chain attack.

Even CrowdStrike’s packages were briefly hit.

They’ve rotated keys and removed the bad versions, but this shows how deep the breach went.

🛡 What you MUST do right now;

-Audit dependencies: Pin versions, re-check package-lock.json or yarn.lock.

-Rotate secrets: Any leaked keys are now burned.

-Scan repos: Use Trivy, Socket, Step Security or Aikido scanners.

-Enable 2FA on NPM & GitHub.

-Watch maintainer accounts: Compromised maintainers are the worm’s fuel.

Supply-chain attacks are getting smart, fast, and relentless.

If you’re in DeFi, NFTs, or any JS-heavy project, one compromised build step can drain wallets or leak critical infra keys.

Don’t sleep on this. Verify.

02

查看 X 原帖 ↗

This is also still relevant

https://t.co/3khWO2LNaR

提及的账号

查找所选文章中提及的 X 账号。被提及不代表受到指控或获得推荐。

@ctrl

相关研究

钓鱼攻击、漏洞与隐私

Privacy, surveillance and control

A discussion of surveillance, data collection and the relationship between privacy and personal autonomy.

原创文章4 min
MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包