<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>供應鏈攻擊 相關文章 - 88sport-news</title>
	<atom:link href="https://www.88sport-news.com/tag/%e4%be%9b%e6%87%89%e9%8f%88%e6%94%bb%e6%93%8a/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>來自台灣與世界的體育新聞與分析</description>
	<lastBuildDate>Tue, 31 Mar 2026 18:09:20 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://www.88sport-news.com/wp-content/uploads/2025/11/cropped-ChatGPT-Image-11-нояб.-2025-г.-12_10_43-32x32.webp</url>
	<title>供應鏈攻擊 相關文章 - 88sport-news</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Axios供應鏈攻擊影響全球開發者</title>
		<link>https://www.88sport-news.com/2026/04/01/axiosgong-ying-lian-gong-ji-ying-xiang-quan/</link>
		
		<dc:creator><![CDATA[陳冠宇]]></dc:creator>
		<pubDate>Tue, 31 Mar 2026 18:09:20 +0000</pubDate>
				<category><![CDATA[趨勢分析]]></category>
		<category><![CDATA[axios]]></category>
		<category><![CDATA[OpenClaw]]></category>
		<category><![CDATA[供應鏈攻擊]]></category>
		<category><![CDATA[安全漏洞]]></category>
		<category><![CDATA[開發者]]></category>
		<guid isPermaLink="false">https://www.88sport-news.com/2026/04/01/axiosgong-ying-lian-gong-ji-ying-xiang-quan/</guid>

					<description><![CDATA[<p>axios遭遇供應鏈攻擊，影響每週高達3億次下載的開發環境。開發者應立即檢查使用版本以確保安全。</p>
<div class="read-more-wrapper"><a class="read-more" href="https://www.88sport-news.com/2026/04/01/axiosgong-ying-lian-gong-ji-ying-xiang-quan/" title="閱讀更多"> <span class="button ">閱讀更多</span></a></div>
<p><a href="https://www.88sport-news.com/2026/04/01/axiosgong-ying-lian-gong-ji-ying-xiang-quan/">Axios供應鏈攻擊影響全球開發者</a>最先出现在<a href="https://www.88sport-news.com">88sport-news</a>。</p>
]]></description>
										<content:encoded><![CDATA[<h2></h2>
<p>2026年3月31日，axios遭遇供應鏈攻擊，影響每週高達3億次下載的開發環境。這一事件由Socket Security研究員Feross Aboukhadijeh揭露，指出攻擊者只需短時間釋出惡意版本，就能在全球範圍內隨機感染開發者環境。</p>
<p>此次攻擊涉及兩個受污染版本，分別為[email protected]與[email protected]，這些版本內部引入了一個全新套件[email protected]。該惡意套件具備執行shell指令、下載並部署後續payload的能力，對開發者造成重大威脅。</p>
<p>Karpathy指出，這是一次「高度危險的供應鏈事件」。他強調，套件管理的預設行為必須改變，否則單點感染就能透過未鎖定依賴在大規模用戶中擴散。</p>
<p>此外，OpenClaw的最新3.28版可能引入遭供應鏈投毒的axios套件，開發者應立即透過npm ls axios確認當前使用版本，並鎖定在安全版本。</p>
<p>根據報導，MEDIA協議存在Prompt注入高危漏洞，影響全球逾17萬個公開存取的實例。CNNVD已累計收錄82個OpenClaw相關漏洞，顯示出此次事件的嚴重性。</p>
<p>為了防範此類攻擊，專家建議開發者導入自動化安全掃描工具，例如Socket Security、StepSecurity或Trivy，以提高安全性。</p>
<p>攻擊者針對不同作業系統量身打造了專屬載荷，這使得攻擊的影響範圍更加廣泛。開發者必須保持警惕，隨時檢查和更新其使用的套件。</p>
<p>目前，對於此次攻擊的詳細情況仍未確認，開發者應持續關注相關資訊以確保其環境的安全。</p>
<p><a href="https://www.88sport-news.com/2026/04/01/axiosgong-ying-lian-gong-ji-ying-xiang-quan/">Axios供應鏈攻擊影響全球開發者</a>最先出现在<a href="https://www.88sport-news.com">88sport-news</a>。</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>LiteLLM 供應鏈攻擊事件</title>
		<link>https://www.88sport-news.com/2026/03/25/litellm-gong-ying-lian-gong-ji-shi-jian/</link>
		
		<dc:creator><![CDATA[林雅婷]]></dc:creator>
		<pubDate>Wed, 25 Mar 2026 08:59:40 +0000</pubDate>
				<category><![CDATA[趨勢分析]]></category>
		<category><![CDATA[Endor Labs]]></category>
		<category><![CDATA[LiteLLM]]></category>
		<category><![CDATA[TeamPCP]]></category>
		<category><![CDATA[供應鏈攻擊]]></category>
		<category><![CDATA[安全漏洞]]></category>
		<category><![CDATA[惡意程式碼]]></category>
		<category><![CDATA[數據竊取]]></category>
		<category><![CDATA[開源軟體]]></category>
		<guid isPermaLink="false">https://www.88sport-news.com/2026/03/25/litellm-gong-ying-lian-gong-ji-shi-jian/</guid>

					<description><![CDATA[<p>LiteLLM 發生供應鏈攻擊，駭客竊取了大量憑證，影響了數百萬用戶。</p>
<div class="read-more-wrapper"><a class="read-more" href="https://www.88sport-news.com/2026/03/25/litellm-gong-ying-lian-gong-ji-shi-jian/" title="閱讀更多"> <span class="button ">閱讀更多</span></a></div>
<p><a href="https://www.88sport-news.com/2026/03/25/litellm-gong-ying-lian-gong-ji-shi-jian/">LiteLLM 供應鏈攻擊事件</a>最先出现在<a href="https://www.88sport-news.com">88sport-news</a>。</p>
]]></description>
										<content:encoded><![CDATA[<h2>What observers say</h2>
<p>「駭客會搜刮憑證，包括：SSH金鑰、雲端權杖（Token），以及Kubernetes密鑰等。」這句話揭示了LiteLLM供應鏈攻擊的嚴重性，該事件於2026年3月24日被安全公司Endor Labs確認。</p>
<p>LiteLLM是一個開源的Python庫，廣泛用於整合多個AI模型API。此次攻擊影響了LiteLLM的1.82.7和1.82.8版本，這些版本被植入了惡意程式碼，並在Python Package Index（PyPI）上可供下載，月下載量高達9500萬次。</p>
<p>根據Endor Labs的報告，這次攻擊採用了三階段的機制：憑證收集、數據外洩和橫向移動。惡意程式碼被隱藏在proxy_server.py文件中，利用Python的.pth機制進行執行，這使得攻擊者能夠在不被發現的情況下竊取用戶的敏感信息。</p>
<p>此次攻擊的惡意版本在PyPI上流傳，並且造成了約300GB的數據外洩，包括500,000個憑證。用戶被建議如果安裝了受影響的版本，應立即更換所有憑證。安全專家指出，最後一個安全版本為1.82.6。</p>
<p>此次攻擊與之前Trivy安全掃描器的漏洞有關，顯示出開源軟體在安全性方面的脆弱性。駭客組織TeamPCP被指控發起這次攻擊，並使用假域名models.litellm.cloud來外洩數據。</p>
<p>這一事件再次引發了對開源軟體安全性的關注，許多開發者和企業開始重新評估他們的安全措施，以防範類似的攻擊。隨著開源軟體在AI應用中的廣泛使用，這類攻擊的風險也隨之增加。</p>
<p>目前，安全專家正在持續調查此次事件的具體細節，並尋求進一步的防範措施。Details remain unconfirmed。</p>
<p><a href="https://www.88sport-news.com/2026/03/25/litellm-gong-ying-lian-gong-ji-shi-jian/">LiteLLM 供應鏈攻擊事件</a>最先出现在<a href="https://www.88sport-news.com">88sport-news</a>。</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
