🚨 又一波 NPM 供应链攻击!
@ctrl/tinycolor(周下载 220 万)推送恶意版本,npm postinstall 会运行信息窃取器,利用 TruffleHog 扫描并外泄敏感数据/密钥。
赶紧检查你的依赖:你安装过这个包吗?

From X
Disclaimer: The above content reflects only the author's opinion and does not represent any stance of CoinNX, nor does it constitute any investment advice related to CoinNX.

