1
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
npm 蠕虫 Shai-Hulud 骗过了安全检查——不是靠伪造,而是真拿到了合法证书。软件供应链攻击正在升级,开发者生态全线告急,值得每个工程师警惕。
An attacker on Tuesday took over the GitHub account of the developer who maintains keyv , a small key-value storage library that npm serves roughly 12…