🕵️ SicherheitslückenSQLi & XSS Vulnerabilities in a Popular Airlines Website!(10.10.2017 um 20:34 Uhr)
🕵️ SicherheitslückenBugcrowd’s Domain & Subdomain Takeover vulnerability!(10.10.2017 um 21:20 Uhr)
🕵️ SicherheitslückenUnrestricted File Upload to RCE | Bug Bounty POC(19.12.2017 um 13:48 Uhr)
🕵️ SicherheitslückenHow I was able to Bypass XSS Protection on HackerOne's Private Program(02.02.2018 um 13:10 Uhr)
🕵️ SicherheitslückenIOS 11.4 Siri Auth Bypass | CVE-2018-4238(22.05.2018 um 15:31 Uhr)
🪟 Windows TippsHow to Enable Windows 11 Screen Savers(07.09.2026 um 12:41 Uhr)
🪟 Windows TippsMicrosoft Phone Link Not Showing Messages on Windows 11? Fix It(09.09.2026 um 07:52 Uhr)
🕵️ SicherheitslückenSQLi & XSS Vulnerabilities in a Popular Airlines Website!(10.10.2017 um 20:34 Uhr)
🕵️ SicherheitslückenBugcrowd’s Domain & Subdomain Takeover vulnerability!(10.10.2017 um 21:20 Uhr)
🕵️ SicherheitslückenUnrestricted File Upload to RCE | Bug Bounty POC(19.12.2017 um 13:48 Uhr)
🕵️ SicherheitslückenHow I was able to Bypass XSS Protection on HackerOne's Private Program(02.02.2018 um 13:10 Uhr)
🕵️ SicherheitslückenIOS 11.4 Siri Auth Bypass | CVE-2018-4238(22.05.2018 um 15:31 Uhr)
🪟 Windows TippsHow to Enable Windows 11 Screen Savers(07.09.2026 um 12:41 Uhr)
🪟 Windows TippsMicrosoft Phone Link Not Showing Messages on Windows 11? Fix It(09.09.2026 um 07:52 Uhr)

📰 IT Security Nachrichten 🕛 vor 3 Monaten 4 Min Lesezeit SECURITY-FEED
0

AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks

↗ Quelle (csoonline.com)
🗣️ Stimme:
📑 Inhaltsübersicht








The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, this time targeting the widely-used AntV enterprise data visualization tool.





Unlike last week’s high-profile npm attack , the account in question, atool ([email protected]), which publishes the timeago.js JavaScript library, had rights to a large catalog of packages, including popular tools such as size-sensor (4.2 million downloads per month), echarts-for-react (3.8 million), @antv/scale (2.2 million), and timeago.js (1.15 million).





This privilege level allowed the attacker to publish at least 637 malicious versions across 317 different npm packages in a single 22-minute burst. This resulted in the compromise of a big chunk of Alibaba’s AntV namespace, a growing platform across Asia, the US, and Europe used to build dashboards, user interfaces, and interactive applications.





Attacks on the npm supply chain this year plot a challenging trend, , the source code for which was recently briefly released to other criminals on GitHub.





Its purpose is to steal npm and GitHub tokens, as well as credentials from 130 file paths, including multiple cloud platforms, Kubernetes, Docker, Hashicorp, password vaults, SSH keys, and Bitcoin wallets.





For unknown reasons, the attackers then use stolen CI/CD tokens to store exfiltrated data in public GitHub repositories themed on the science fiction novel Dune, which, within hours of this attack, grew to 2,500 in number. Each repository description contains the string “niagA oG eW ereH :duluH-iahS” (“Shai-Hulud: Here We Go Again” backwards).





In theory, the malware is also capable of persistence via a Python-based backdoor installed at ~/.local/share/kitty/cat.py, although , which allows the malware to be stealthily reinstated with full LLM privileges in case the infected npm packages have been removed.





Next steps





After the attack was detected, AntV’s maintainers issued the following as a .csv), although it’s safe to assume that if any version of the AntV library is in use, infection is a possibility.





Beyond that, recommended actions are to look for signs of compromise in CI/CD environments and repositories, and to rotate all credentials.





But the most important advice from experts is much simpler: strengthen defenses against future attacks targeting npm by improving monitoring and package verification.





This article originally appeared on InfoWorld.


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf csoonline.com.
↗ Original-Artikel auf csoonline.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Bugcrowd’s Domain & Subdomain Takeover vulnerability!
1 Quelle
SQLi & XSS Vulnerabilities in a Popular Airlines Website!
1 Quelle
Unrestricted File Upload to RCE | Bug Bounty POC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks

Thematisch verwandte Begriffe: AntV, data, visualization, tool · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...