시가총액: $2.2006T 0.82%
거래량(24시간): $38.5475B -31.41%
  • 시가총액: $2.2006T 0.82%
  • 거래량(24시간): $38.5475B -31.41%
  • 공포와 탐욕 지수:
  • 시가총액: $2.2006T 0.82%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

npm Worm Unleashed: SANDWORM_MODE는 개발 환경을 악용하고 암호화 키와 AI 비밀을 훔칩니다.

2026/02/22 01:45

새로운 npm 웜인 SANDWORM_MODE는 개발자 환경을 적극적으로 표적으로 삼아 개인 키, 암호화폐 자산, AI API 키를 수집합니다. 진화하는 위협 환경에 대해 알아보세요.

npm Worm Unleashed: SANDWORM_MODE는 개발 환경을 악용하고 암호화 키와 AI 비밀을 훔칩니다.

npm Worm Unleashed: SANDWORM_MODE Exploits Dev Environments, Steals Crypto Keys and AI Secrets

npm Worm Unleashed: SANDWORM_MODE는 개발 환경을 악용하고 암호화 키와 AI 비밀을 훔칩니다.

In a startling development for the software development community, a sophisticated npm worm, dubbed SANDWORM_MODE, has been discovered actively compromising developer environments. This self-replicating malware has infiltrated at least 19 malicious npm packages, with a primary objective of harvesting sensitive information, including private keys, cryptocurrency wallet details, and crucial AI API keys.

소프트웨어 개발 커뮤니티의 놀라운 개발 과정에서 SANDWORM_MODE라고 불리는 정교한 npm 웜이 개발자 환경을 적극적으로 손상시키는 것으로 발견되었습니다. 이 자가 복제 악성 코드는 개인 키, 암호화폐 지갑 세부 정보 및 중요한 AI API 키를 포함한 민감한 정보를 수집하는 것이 주요 목표로 최소 19개의 악성 npm 패키지에 침투했습니다.

The SANDWORM_MODE Attack: A Multi-Pronged Assault

SANDWORM_MODE 공격: 다각적인 공격

Uncovered by Socket's Threat Research Team, SANDWORM_MODE represents a significant escalation in supply chain attacks. Unlike previous threats, this worm operates with alarming speed and stealth. Its first stage executes immediately upon package import, focusing on exfiltrating npm tokens, GitHub tokens, environment secrets, and various forms of crypto keys. This includes BIP39 mnemonics, Ethereum private keys, Solana byte arrays, and Bitcoin WIF keys, all sent to a dedicated drain endpoint before any other payload can be triggered.

Socket의 위협 연구팀이 발견한 SANDWORM_MODE는 공급망 공격이 크게 증가했음을 나타냅니다. 이전 위협과 달리 이 웜은 놀라운 속도와 은밀하게 작동합니다. 첫 번째 단계는 패키지 가져오기 즉시 실행되며 npm 토큰, GitHub 토큰, 환경 비밀 및 다양한 형태의 암호화 키를 추출하는 데 중점을 둡니다. 여기에는 BIP39 니모닉, 이더리움 개인 키, 솔라나 바이트 배열, 비트코인 ​​WIF 키가 포함되며, 모두 다른 페이로드가 트리거되기 전에 전용 배수 엔드포인트로 전송됩니다.

Beyond Crypto: Targeting AI and Developer Secrets

암호화폐 너머: AI 및 개발자 비밀 타겟팅

The worm's malicious capabilities extend beyond cryptocurrency theft. It actively injects malicious GitHub workflows and poisons AI toolchains. Several packages impersonate AI coding tools, embedding rogue servers into popular AI assistant configurations. These rogue servers are designed to stealthily prompt AI assistants to exfiltrate SSH keys, AWS credentials, npm tokens, and other environment secrets, all while preventing the AI from notifying the user. Furthermore, the worm targets API keys from major LLM providers, including OpenAI, Anthropic, and Google, by searching environment variables and .env files.

웜의 악의적인 기능은 암호화폐 도난을 넘어 확장됩니다. 악성 GitHub 워크플로를 적극적으로 주입하고 AI 툴체인을 오염시킵니다. 여러 패키지가 AI 코딩 도구를 가장하여 인기 있는 AI 보조 구성에 악성 서버를 내장합니다. 이러한 악성 서버는 AI 보조자가 SSH 키, AWS 자격 증명, npm 토큰 및 기타 환경 비밀을 유출하도록 은밀하게 유도하는 동시에 AI가 사용자에게 알리는 것을 방지하도록 설계되었습니다. 또한 이 웜은 환경 변수 및 .env 파일을 검색하여 OpenAI, Anthropic 및 Google을 포함한 주요 LLM 제공업체의 API 키를 표적으로 삼습니다.

Evolving Threat Landscape and Mitigation

진화하는 위협 환경 및 완화

While npm, GitHub, and Cloudflare have taken action to remove the malicious packages and infrastructure, the threat necessitates immediate action from developers. Any environment that has run these packages should be treated as compromised. Key mitigation steps include rotating all npm and GitHub tokens, auditing CI/CD workflows for suspicious additions, and reviewing AI assistant configurations. The worm's design, which includes a dormant polymorphic engine and a disabled "dead switch" capable of shredding files, indicates that future variants could be even more sophisticated and evasive.

npm, GitHub 및 Cloudflare는 악성 패키지와 인프라를 제거하기 위한 조치를 취했지만 위협으로 인해 개발자는 즉각적인 조치를 취해야 합니다. 이러한 패키지를 실행한 모든 환경은 손상된 것으로 간주되어야 합니다. 주요 완화 단계에는 모든 npm 및 GitHub 토큰 교체, 의심스러운 추가 사항에 대한 CI/CD 워크플로 감사, AI 보조 구성 검토가 포함됩니다. 휴면 다형성 엔진과 파일을 파쇄할 수 있는 비활성화된 "데드 스위치"를 포함하는 이 웜의 설계는 미래의 변종이 훨씬 더 정교하고 회피할 수 있음을 나타냅니다.

A Broader Context: Keys, Bots, and AI Governance

더 넓은 맥락: 키, 봇, AI 거버넌스

This incident underscores a broader debate about control and security in the digital realm, particularly concerning AI. As articulated by crypto investor Balaji Srinivasan, "whoever controls the keys controls the machines." While current AI systems still rely on humans for goal-setting, the potential for AI to gain more autonomy raises questions about governance. Blockchain-based cryptography and private keys are emerging as potential mechanisms for securing AI agents and ensuring they remain aligned with human-defined objectives. The SANDWORM_MODE attack, by focusing on the theft of private keys and API credentials, serves as a stark, albeit malicious, demonstration of the critical importance of securing these digital assets.

이번 사건은 디지털 영역, 특히 AI와 관련된 통제 및 보안에 대한 광범위한 논쟁을 강조합니다. 암호화폐 투자자 발라지 스리니바산(Balaji Srinivasan)은 "키를 통제하는 사람이 기계를 통제한다"고 말했습니다. 현재 AI 시스템은 목표 설정을 위해 여전히 인간에 의존하고 있지만 AI가 더 많은 자율성을 얻을 가능성은 거버넌스에 대한 의문을 제기합니다. 블록체인 기반 암호화 및 개인 키는 AI 에이전트를 보호하고 인간이 정의한 목표에 부합하도록 보장하기 위한 잠재적인 메커니즘으로 떠오르고 있습니다. SANDWORM_MODE 공격은 개인 키와 API 자격 증명의 도용에 중점을 두어 악의적이기는 하지만 이러한 디지털 자산을 보호하는 것이 얼마나 중요한지 극명하게 보여줍니다.

Looking Ahead

미래를 내다보며

The interconnectedness of software supply chains, cryptocurrency, and AI means that security threats are becoming increasingly complex. Vigilance and proactive security measures are paramount for developers and organizations alike. So, let's all keep our digital doors locked and our keys safe – happy coding!

소프트웨어 공급망, 암호화폐, AI의 상호 연결성은 보안 위협이 점점 더 복잡해지고 있음을 의미합니다. 경계와 사전 예방적인 보안 조치는 개발자와 조직 모두에게 가장 중요합니다. 그러니 모두 디지털 도어를 잠그고 열쇠를 안전하게 보관하세요. 즐거운 코딩 되세요!

원본 소스:livebitcoinnews

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年07月26日 에 게재된 다른 기사