Vite 프론트엔드 도구 생태계를 겨냥한 7개의 악성 npm 패키지가 발견됐다.
사이버 보안 연구자들이 Vite 프론트엔드 툴링 생태계를 타겟으로 한 7개의 악성 npm 패키지를 발견했다. 이 공격은 소프트웨어 공급망 공격의 일환으로, Checkmarx에 의해 ViteVenom이라는 코드명이 붙여졌다. 이 캠페인은 Tron에서 네 가지 계층으로 구성된 블록체인 기반의 명령 및 제어(C2) 인프라를 사용해 이전에 없던 방식으로 진행되고 있다.
Seven malicious npm packages targeting Vite frontend tooling discovered.
Cybersecurity researchers have identified seven malicious npm packages targeting the Vite frontend tooling ecosystem. This attack is part of a software supply chain attack, dubbed ViteVenom by Checkmarx. The campaign utilizes an unprecedented four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron.