최신 보도, 해설 및 관련 기술 스토리를 확인하세요.
Microsoft Threat Intelligence analyzed a widespread attack on the npm supply chain in which a credential-stealing worm hid inside more than 400 packages published by different parties. The malware collects secrets from developers and CI/CD environments, then uses npm and GitHub tokens to republish malicious versions and open additional propagation paths.