🚨 又一波 NPM 供应链攻击! @ctrl/tinycolor(周下载 220 万)推送恶意版本,npm postinstall 会运行信息窃取器,利用 TruffleHog 扫描并外泄敏感数据/密钥。 赶紧检查你的依赖:你安装过这个包吗?
From X

Disclaimer: The above content reflects only the author's opinion and does not represent any stance of CoinNX, nor does it constitute any investment advice related to CoinNX.