Chete 9.27% ​​yeNPM mapakeji vanochengeta vanoshandisa maviri-chinhu chechokwadi

Adam Baldwin, anotungamira timu ine basa rekuchengetedza NPM repository, rakabudiswa nhamba dzakagadzirirwa kubva pane zvakabuda gore rapfuura:

  • Kunyangwe inoenderera mberi zviitiko nekutora kweNPM repositories, chete 9.27% ​​yevagadziri vepasuru vanoshandisa mbiri-zvinhu kuvimbiswa kuchengetedza kupinda;
  • Paunenge uchinyoresa, 13.37% yemaakaundi matsva akaedza kushandisazve mapassword akakanganiswa akaonekwa mune inozivikanwa password yekuvuza, zvinoenderana nesevhisi. haveibeenpwned.com;
  • Gore rakapera, 737 NPM tokens dzakabviswa nokuti dzakakanganisa rakabudiswa muNPM package registry kana marepositori anowanika pachena paGitHub;
  • Averted kubiwa kwe $ 13 mamiriyoni mu cryptocurrency nekuda kwekuwanikwa kwekuedza kubatanidza backdoor muchikwama cheKomodo Agama;
  • Huwandu hwenyaya dzekuchengetedza mishumo muNPM dhatabhesi yasvika 1285, iyo 595 mishumo yakagadzirwa muna 2019. Kuburikidza [email inodzivirirwa] 2.2 zviuru zviziviso nezve kuvapo kwekusagadzikana kwakagamuchirwa;
  • Mukufamba kwegore, iyo antispam system yakavharira 11526 kutengeserana, kusanganisira izvo zvine chekuita nekuedza kukurudzira kushambadza kwemvura uye mafirimu;
  • Analysis system maitiro asina kunaka yakagadzira 1.4 miriyoni mishumo yakakumbirwa kuburikidza neAPI, inovhara 15.6 TB yedata ine ruzivo rwekuongorora maitiro.

Source: opennet.ru

Voeg