Replies: 11 comments 29 replies
|
After investigation, it was found that the token of one of our team members might have been stolen. We are handling it urgently. 经排查可能是我们团队一名成员的 token 被盗用了,我们正在紧急处理 |
|
A new and secure version has been released, and the npm latest tag already points to the new version: 已发布安全的新版本,npm latest tag 已经指向新版本: The following are deprecated versions, please do not use 以下是已经废弃的异常版本,请勿使用
|
|
与本次事件关联的攻击: 攻击者基于一系列攻击,获取了 Rspack 维护者的 token,并发布了带有相同恶意代码的 Rspack 1.1.7 版本。 Rspack 团队已经在一小时内完成该版本的废弃处理,并发布了 1.1.8 修复版本,参考 web-infra-dev/rspack#8767 (comment) 目前相关 token 已经全部清理。 |
|
这个安全漏洞会导致什么bug或者情况呢 |
|
请问问题版本具体的发布时间是什么时候,我们需要确认近两天刚发布的版本有没有受影响 |
|
hi 如何检查自己是否中了,能给一个自检流程吗?在lock文件中找版本? |
|
我之所以能比较早发现这个,是因为我有一个习惯,首先业务项目带lock, 然后想要更新依赖时,先npm outdated检查版本,发现有新版本时在更新前都会去GitHub看一下changelog, 从changelog里面判断是不是有不兼容更新,是否可以不做修改直接升级,由此才比较早发现这个。 |
|
怎么检查一下自己电脑有没有中招哇 |
|
vant-weapp小程序包有没有注入恶意代码? |


Uh oh!
There was an error while loading. Please reload this page.
All reactions