Security Firm Cryptocurrency Theft Tool TrapDoor Targets Top Three Code Repositories, 34 Malicious Packages Detected
BlockBeats News, May 25th, according to the security company Socket Security, a cryptocurrency theft activity named TrapDoor is conducting a supply chain attack in package repositories such as npm, PyPI, and Crates.io. Currently, 34 malicious packages and 384 versions and builds have been identified, with the attackers continuously pushing new versions across the ecosystems.
The article states that TrapDoor mainly targets developers in the cryptocurrency, AI, and security fields, capable of stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, environment variables, and API keys.
來源:BlockBeats
免責聲明:當前內容均來自第三方觀點或由AI直接翻譯第三方觀點,CoinEx不保證內容的真實性、準確性和原創性,不構成CoinEx相關的任何投資建議。數字資產價格波動劇烈,請注意潛在風險。
相關快訊
熱搜榜
- 幣種價格24H漲跌