跳到正文
@kimmonismus· @kimmonismus · X·· 2026-05-13AI 评分64
AI 导读

Aikido 更新称,本轮 npm 供应链攻击已从 TanStack 和 Mistral 扩展至 169 个 npm 包名,共涉及 373 个恶意包版本条目,波及 @uipath、@squawk、@tallyui、@beproduct 等。该恶意程序通过窃取 CI 凭证并利用其发布新的被感染版本来传播。Aikido 公布了完整的 IOC、受影响包列表和检测步骤。

正文

What a timing. I just talked to Aikido’s co-founder and talked about the rise of attacks due to AI.

Well: here we are. Video down below:

引用Aikido Security (@AikidoSecurity)@AikidoSecurity
Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral. 373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more. The malware propagates by stealing your CI credentials and using them to publish new compromised versions. Full IOCs, affected package list, and detection steps: aikido.dev/blog/mini-shai-hu…
在 X 查看被引用的帖子

来源:@kimmonismus · x.com