T
traeai
Sign in

产品

Session / Oxen

别名:session、oxen

去中心化通信与数据加密平台,被攻击者用于外传窃取数据。

已跟踪 1 条高相关材料

TraeAI 观察

最近变化

2026-05-12 · 攻击者利用 GitHub Actions 的 pull_request_target 漏洞与跨 fork 缓存投毒,绕过双重验证完成恶意发布。

为什么值得关注

Session / Oxen 被反复提及时,通常意味着它正在影响产品路线、开发者工作流或 AI 产业判断。这个页面把分散材料合并成一个可持续更新的观察入口。

GitHub Actionsnpm供应链攻击安全漏洞开源生态

相关材料

已收录 1 条与 Session / Oxen 相关的内容,按评分排序。

npm 生态遭大范围投毒:TanStack、Mistral AI、UiPath 等受波及,可窃取云密钥与 GitHub 令牌

A large-scale supply chain attack hit the npm ecosystem, affecting over 160 packages including TanStack, Mistral AI, and UiPath; attackers used GitHub Actions vulnerabilities and OIDC tokens to publish malicious code under trusted identities.

入选理由:攻击者利用 GitHub Actions 的 pull_request_target 漏洞与跨 fork 缓存投毒,绕过双重验证完成恶意发布。

FeaturedArticle#npm#supply chain attack#GitHub Actions#security vulnerability#open source ecosystem中文

跨材料问答 · Session / Oxen

回答基于:Session / Oxen 相关 1 条材料
    0 / 500

    AI may generate inaccurate information. Please verify important content.