[KongchangAI]
Unverified50% confidenceFactExact time

Shai-Hulud 攻击载荷通过 postinstall 等生命周期脚本扫描本地敏感信息,包括 npm 令牌、AWS/GCP/Azure 云凭证、环境变量密码及 CI/CD 部署密钥

1
Sources
50%
Confidence
Medium-term (~90 days)
Relevance
8/8/2026
First Seen
Valid until: 11/6/2026

Sources

Related Claims

Cite This Claim

Stable URI
https://kongchang.com/claim/705759
API
curl https://kongchang.com/api/v1/knowledge/claims/705759
MCP
get_claim(id=705759)