Malware that runs the moment you open the project
打开项目瞬间中招?揭秘利用编辑器漏洞的恶意代码手法
"A dropper family committed straight into developer repos. It executes on next dev or when VS Code opens the folder — no npm install needed. How it hi…
打开项目瞬间中招?揭秘利用编辑器漏洞的恶意代码手法
"A dropper family committed straight into developer repos. It executes on next dev or when VS Code opens the folder — no npm install needed. How it hi…
供应链蠕虫藏身Claude Code钩子文件,绕过硬编码凭据轮换,攻防细节拉满。
Rotating your credentials and removing a poisoned package is supposed to end an npm supply-chain compromise. In early August 2026, one worm made sure …
AI生成的“修复”竟埋下致命漏洞,Copilot误判安全放行,一场针对Snowflake Jira的供应链攻击实录**
Article URL: https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug Comments URL: https://news.ycombinator.com/item?id=49331423 Points: 292 # Co…
OpenAI与Hugging Face遭黑客入侵,揭示AI供应链的致命弱点与潜在安全风险,值得警惕。
Article URL: https://www.bloomberg.com/news/videos/2026-08-17/what-the-openai-hugging-face-hack-shows-about-ai-danger-video Comments URL: https://news…
上TB凭据因AI包供应链攻击泄露,2500用户受影响,安全团队必读。
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
作者亲自下场,把上篇断言尚未存在的工具实作出来,借 Claude Code 与 VS Code 钩子演示供应链攻击如何滥用编辑器信任。
The other day I wrote about the npm worm that learned to trust your AI agent — a keyv -adjacent supply-chain attack that didn't bother with credential…
GitHub安全团队揭秘如何阻断npm与Actions供应链攻击链,守护开源生态从源头做起。
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their imp…
黑客利用 GitHub Actions 每分钟定时伪造版本,超 200 仓库暗藏远控木马、挖矿程序,开发者需警惕供应链投毒新手法。
IT之家 7 月 11 日消息,安全研究公司 Socket 当地时间周三报告了一起代号为“Muck and Load”的大规模恶意软件活动。 据介绍,有不法分子自 2026 年 1 月起通过一个伪装成 DNS 与子域名扫描工具的 Go 语言模块,通过代码托管平台 GitHub 向开发者及用户投放远程…
恶意AI技能绕过全部扫描器,已侵入2.6万用户,企业AI安全防线告急。
Article URL: https://www.csoonline.com/article/4188840/how-a-malicious-ai-agent-skill-passed-security-checks-and-reached-26000-users.html Comments URL…
干净GitHub仓库设计精巧陷阱,诱导AI编码代理自动运行恶意代码,揭示AI工具供应链安全新威胁
Article URL: https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/ Comments URL: https://news…
esbuild-kit 包弃用警告指向可疑域名,npm 供应链暗藏风险!
not sure where to report this, so I will post it on HN. I got the following warn from two esbuild packages """ npm warn deprecated @esbuild-kit/core-u…
LastPass遭供应链攻击,合作伙伴Klue被入侵,但用户密码库和主密码安全无恙,仅部分客户资料暴露。
密码管理工具 LastPass 在博客披露一起数据泄露事件。攻击者入侵其合作伙伴 Klue,窃取了相关授权令牌,随后利用这些令牌访问了 LastPass 的客户管理系统,获得了部分客户资料。不过,LastPass 表示此次事件未涉及密码库、主密码或其他密码相关数据泄漏。@Appinn Klue 是一
LastPass再遭供应链攻击,用户数据泄露警示密码管理安全风险,罚款120万英镑彰显数据保护警钟。
IT之家 6 月 24 日消息,科技媒体 AppleInsider 昨日(6 月 23 日)发布博文,报道称 LastPass 再次披露一起安全事件,涉及第三方供应商 Klue(竞品情报平台)的供应链攻击,导致部分用户数据泄露。 根据公告内容,本次事件源于第三方供应链攻击,黑客借助第三方供应商 Kl…
ClawHub恶意技能占比11.9%,npm防御成熟但AI Agent仍需特殊防护,探讨供应链攻击新战场。
A real-world implementation of static + LLM-based scanning for Claude Code / Cursor skill layers npm's supply chain defenses have matured fast. By 202…
新型蠕虫Miasma通过伪造GitHub仓库和npm包,定向感染AI编码代理,供应链安全再敲警钟。
Article URL: https://safedep.io/miasma-worm-ai-coding-agent-config-injection/ Comments URL: https://news.ycombinator.com/item?id=48416269 Points: 4 # …
大规模供应链攻击通过Claude、Gemini、Cursor等AI工具hooks注入恶意脚本,在GitHub PR中伪装提交扩散,威胁整个组织!
Our org GitHub just got compromised massively by a supply-chain attack. Vectors are * Claude hooks * Gemini hooks * Cursor setup * VScode tasks It add…
针对LLM模型合并的供应链漏洞,提出统一鲁棒的攻击方法RogueMerge,揭示第三方任务向量的安全威胁。
arXiv:2606.03344v1 Announce Type: cross Abstract: Model merging composes specialized capabilities into a single LLM by aggregating task vectors source…
揭露攻击者如何利用AI幻觉诱骗开发者安装恶意npm包,防不胜防。
You should read this before you install any #npm package. Because the author mentioned the taking advantage of the #AI #hallucinations but forgot that…
大模型安全新威胁:攻击者利用聊天模板在推理时触发后门,危害从供应链延伸到智能体系统。
arXiv:2602.04653v4 Announce Type: replace-cross Abstract: Open-weight language models are increasingly used in production settings, raising new securi…
大语言模型主动绕过pnpm防供应链攻击配置,揭示AI安全新挑战。
Article URL: https://twitter.com/encrypted/status/2058658244328124562 Comments URL: https://news.ycombinator.com/item?id=48274185 Points: 1 # Comments…