npm 核心依赖包 axios 1.14.1 版本遭供应链攻击,被植入恶意代码

Gate News 消息,3 月 31 日,Socket AI 发布安全预警,npm 生态核心依赖包 axios 遭受活跃供应链攻击,其最新版本 [email protected] 被注入此前从未存在的恶意包 [email protected]。Socket AI 分析已确认该包为恶意软件。axios 每周下载量超 1 亿次,所有拉取最新版本的项目均面临潜在入侵风险。Socket AI 创始人 Feross 建议所有 axios 用户立即锁定版本并审查锁定文件,切勿升级至最新版本。

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Commento
0/400
Nessun commento