Malicious packages in npm. Hereâs what to do | Ivan Akulovâs blog People found malicious packages in npm that work like real ones, are named similarly real ones, but collect and send your process environment to a third-party server when you install them 訳: æªæã®ããããã±ã¼ã¸ãnpmã§çºè¦ãããããããã¯ãå®éã®ããã±ã¼ã¸ã«ããä¼¼ãååã§åãããã«åãããããã±ã¼ã¸ã®ã¤ã³ã¹ãã¼ã«æã«ããã»ã¹ã®ç°å¢å¤æ°ãå¤é¨ã®ãµã¼ãã«éä¿¡ããã çºè¦ãããããã±ã¼ã¸ã®ä¸è¦§ã¯å ã¨ã³ããªãã©ããããã®ãããªãã«ã¦ã§ã¢ã§ããå½ããã±ã¼ã¸ã®ä¸ä¾ããããã¨ã ba
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}