ended5월 12일· 1 sources
Massive npm Supply Chain Infiltration Targets Developer Ecosystem Giants
계정 탈취 없는 대규모 npm 공급망 공격, TanStack과 Mistral AI를 조준하다
Why it matters
This massive npm campaign highlights the evolving sophistication of supply chain attacks, targeting trusted libraries like TanStack and Mistral AI without needing to breach maintainer accounts. It signals a critical shift in attack vectors, necessitating more rigorous and automated dependency auditing for modern software development.
1
Sources
+0
24h
—
Growth
132d
Active
npmSupply Chain AttackTanStackMistral AICybersecurityMalware