네 개의 손상된 AsyncAPI npm 패키지가 멀티 스테이지 봇넷 악성코드를 배포하고 있다.
OX Security, SafeDep, Socket, StepSecurity의 조사에 따르면, 네 개의 손상된 npm 패키지가 멀티 스테이지 봇넷 로더를 배포하고 있는 것이 확인되었습니다. 영향을 받은 패키지에는 @asyncapi/generator-helpers, @asyncapi/generator-components, @asyncapi/generator 및 @asyncapi/specs가 포함됩니다. 사용자들은 이러한 패키지를 사용 시 주의가 필요합니다.
Four compromised AsyncAPI npm packages are found distributing multi-stage botnet malware.
According to findings from OX Security, SafeDep, Socket, and StepSecurity, four compromised npm packages in the @asyncapi namespace are distributing a multi-stage botnet loader. The affected packages include @asyncapi/generator-helpers, @asyncapi/generator-components, @asyncapi/generator, and @asyncapi/specs. Users should exercise caution when using these packages.