Ke 9.27% ​​feela ea bahlokomeli ba liphutheloana tsa NPM ba sebelisang netefatso ea lintlha tse peli

Adam Baldwin, ea etellang pele sehlopha sa tšireletso sa polokelo ea NPM, e hatisitsoeng lipalo-palo tse lokisitsoeng ho ipapisitsoe le liphetho tsa selemo se fetileng:

  • Ho sa natsoe e tsoelang pele diketsahalo ka ho nkuoa ha polokelo ea NPM, ke 9.27% ​​feela ea bahlokomeli ba liphutheloana ba sebelisang netefatso ea lintlha tse peli ho sireletsa phihlello;
  • Ha o ingolisa, 13.37% ea li-account tse ncha li lekile ho sebelisa li-password tse senyehileng tse hlahileng ho lutla ha li-password tse tsebahalang, ho latela ts'ebeletso. haveibeenpwned.com;
  • Selemong se fetileng, li-tokens tsa 737 NPM li ile tsa hlakoloa hobane li ne li fositse phatlalalitsoe ka har'a ngoliso ea liphutheloana tsa NPM kapa lipolokelo tse fumanehang phatlalatsa ho GitHub;
  • Qhisitsoe bosholu ba liranta tse limilione tse 13 ka chelete ea crypto ka lebaka la ho sibolloa ha boiteko ba ho kopanya backdoor ka mokotleng oa Komodo Agama;
  • Palo eohle ea litlaleho tsa litaba tsa ts'ireletso polokelong ea NPM e fihlile ho 1285, moo litlaleho tse 595 li lokisitsoeng ka 2019. Ka [imeile e sirelelitsoe] Ho ile ha amoheloa litsebiso tse likete tse 2.2 mabapi le boteng ba bofokoli;
  • Ho theosa le selemo, tsamaiso ea antispam e ile ea thibela litšebelisano tsa 11526, ho kenyelletsa le tse amanang le boiteko ba ho khothalletsa lipapatso tsa melapo e phoroselang le lifilimi;
  • Sistimi ea tlhahlobo boitšoaro bo sa tloaelehang e hlahisitse litlaleho tse limilione tse 1.4 tse kopiloeng ka API, tse koahelang 15.6 TB ea data e nang le boitsebiso ba tlhahlobo ea boitšoaro.

Source: opennet.ru

Eketsa ka tlhaloso