网络安全研究人员发现了四个恶意NuGet包,专门针对ASP.NET网络应用开发者,旨在窃取敏感数据。 这一攻击活动由Socket公司发现,能够窃取ASP.NET身份数据,包括用户账户、角色分配和权限映射,同时操控授权规则在受害应用中创建持久性后门。
Four rogue NuGet packages and one npm package stole ASP.NET Identity data, deployed C2 backdoors, and reached over 50,000 ...
A:SANDWORM_MODE是一个活跃的供应链蠕虫攻击活动,利用至少19个恶意npm包实施凭据收集和加密货币密钥窃取。它具备窃取系统信息、访问令牌、环境机密和API密钥的能力,并能通过滥用被盗的npm和GitHub身份自动传播扩大影响。
The module targets Claude Code, Claude Desktop, Cursor, Microsoft Visual Studio Code (VS Code) Continue, and Windsurf. It also harvests API keys for nine large language models (LLM) providers: ...
This is a continuation and modernization of the original Auto-Vote-Rating project. Special thanks to Serega007 and all original developers for their incredible work and for creating such a useful tool ...