TrapDoor: The Campaign That Turned AI Coding Assistants Into Attackers
中文摘要
攻击者在六天内向 npm、PyPI 等平台注入 384 个毒化包,利用不可见提示词攻击 AI 编程助手。
English Summary
An attacker deployed 384 poisoned packages across npm, PyPI, and Crates.io, using invisible prompts to target AI coding assistants.
Original Excerpt
An attacker shipped 384 poisoned package versions across npm, PyPI, and Crates.io in six days. Tried to slip invisible prompts past the… Continue reading on Medium »