Iinkcukacha ze-axios NPM package maintenancer credential hijacking zityhilwe

Umgcini wephakheji ye-axios NPM, apho kukhutshwe khona uhlaziyo olubi, utyhile iinkcukacha zohlaselo oluvumele abahlaseli ukuba bafumane ukufikelela kwikhompyutha yakhe kunye nazo zonke iziqinisekiso zakhe. Olu hlaselo lwenziwe kusetyenziswa indlela eqhelekileyo yobunjineli bezentlalo eyayisetyenziswa ngaphambili ukuphazamisa abaphuhlisi bee-wallet ze-crypto kunye namaqonga e-AI.

Lo mhlaseli wazenza umseki wenkampani eyaziwayo waza wacebisa iprojekthi edibeneyo. Ekuqaleni, umxhasi wamenywa kwindawo yokusebenza yaseSlack eyayibonakala ngathi iyinyani, ineendlela ezinemiyalezo yeLinkedIn, kwaye ineeprofayili zobuxoki zabasebenzi benkampani kunye nabameli bezinye iiprojekthi zikawonke-wonke.

Emva kwexesha elithile, kwacwangciswa ingxoxo yeqela, yaququzelelwa kusetyenziswa iqonga le-MS Teams. Ngexesha lentlanganiso, kwavela ubunzima kwezobuchwepheshe, kwatyholwa ukuba akukho songezo sifunekayo kwicala lomgcini-zihlangu. Umgcini-zihlangu wafaka icandelo elilahlekileyo, elathi labonakala liyiTrojan horse, nto leyo eyanika abahlaseli ithuba lokufikelela kwinkqubo kude. Isiganeko sonke sasicwangcisiwe ngobuchule kwaye sabonakala sinokwenzeka.

umthombo: opennet.ru

Thenga ukusingathwa okuthembekileyo kwiindawo ezinokhuseleko lweDDoS, iiseva zeVPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekileyo ngokhuseleko lwe-DDoS, iiseva zeVPS VDS | ProHoster