Shibata, Tats
11.4K posts

Shibata, Tats
@rewse
@awscloud の Head of Japan Data Solutions Architecture。好きなAmazonの段ボール箱はXM05。発言は個人の見解です
東京 | Tokyo Katılım Nisan 2007
1.3K Takip Edilen1K Takipçiler
Shibata, Tats retweetledi

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English

@Keisuke69 1番目は、指定席にするにはHH:MM発のN号の席と指定しなければいけないけど、遅延もよくある普通列車でそれは現実的に難しいからとどこかで読みました。そう言われると「とりあえず来た電車に乗れば良い」自由席もメリットありますね
日本語










