Cremit
/incidentsfield log
탐지캠페인유출지패턴LLM사고 사례방법론
↺rss↗cremit.io

incidents.cremit.io

실제 발생한 비인간 식별자(NHI) 크리덴셜 유출 사고를 정리한 인덱스. 운영: Cremit

둘러보기

  • 전체 사고
  • npm 공급망
  • CI/CD 침해
  • 방법론

구독

  • RSS 피드
  • @cremit_io
  • GitHub
// 상태
모니터 가동중
// 빌드
2026-05-20
// 출처
cremit · 서울, 대한민국
// 라이선스
CC BY 4.0

© 2026 Cremit. 출처 표시 시 자유롭게 재사용 가능.

캠페인/owner-change 웨이브

active

재발화 #36
members
20
합산 blast
930K/wk
마지막 알림
1h ago
2026-05-20
발화 횟수
36
최초 알림 19h ago

// 멤버

최근 7일 동안 이 클러스터의 axis 조건에 현재 매치되는 모든 catch 패키지를 라이브로 재계산. 스니펫은 클러스터 식별자가 static excerpt 어디에 나타나는지(또는 어떤 takeover 휴리스틱이 발화했는지) 보여줍니다.

// 이 웨이브에 포함된 publisher

같은 웨이브를 현재 publisher 기준으로 분리. 기업 소유권 이관(bot 하나가 scoped 이름 여러 개를 푸는 경우)과 실제 dormant takeover(서로 무관한 dormant 메인테이너들이 동시에 발화하는 경우)는 모양이 다릅니다. 분리해서 보면 그 차이가 드러납니다.

iaaron·3개 패키지·71K/wk
  • npm/·@1.0.5·18h ago·

    prev: baizn@1.0.4

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@2.4.1·18h ago·

    prev: pomelo-nwu@2.4.0

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@0.8.24·71K/wk·18h ago·
    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 3 known-vendor host(s), 1 other host(s).

·3개 패키지·70K/wk
  • npm/·@0.8.25·18h ago·

    prev: iaaron@0.8.24

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@0.8.25·18h ago·

    prev: iaaron@0.8.24

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@0.8.25·70K/wk·18h ago
·3개 패키지·125K/wk
  • npm/·@2.0.1-beta.0·18h ago·

    prev: panyuqi@1.8.7

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 2 known-vendor host(s).

  • npm/·@2.1.28-beta.0·63K/wk·18h ago·
    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 2 known-vendor host(s).

  • npm/·@2.1.23-beta.0·62K/wk·
·2개 패키지·45K/wk
  • npm/·@1.0.55·32K/wk·18h ago·
    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@2.0.5·13K/wk·18h ago·
    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 2 known-vendor host(s), 1 other host(s).

·2개 패키지·120K/wk
  • npm/·@0.2.2·120K/wk·18h ago·
    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@0.1.3·19h ago·

    prev: zqlu@0.1.2

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

·2개 패키지·144K/wk
  • npm/·@2.0.4·19h ago·

    prev: atool@2.0.3

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

  • npm/·@0.2.5·144K/wk·19h ago·

    prev: atool@0.2.3

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

·1개 패키지
  • npm/·@3.0.7·18h ago·

    prev: alanwei0@3.0.6

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

·1개 패키지
  • npm/·@0.2.0·18h ago·

    prev: atool@0.1.2

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

·1개 패키지
  • npm/·@0.0.11·18h ago·

    prev: lviser@0.0.10

    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 2 known-vendor host(s).

·1개 패키지·354K/wk
  • npm/·@5.4.8·354K/wk·18h ago·
    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s).

·1개 패키지·1.3K/wk
  • npm/·@3.6.0-alpha.0·1.3K/wk·19h ago·
    recent-owner-change

    llm: No suspicious destination, no remote-exec shape — 2 known-vendor host(s).

·banxuan

prev: iaaron@0.8.24

recent-owner-change

llm: No suspicious destination, no remote-exec shape — 2 known-vendor host(s), 1 other host(s).

18h ago
·alex_zjt
recent-owner-change

llm: No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).

@antv/graphin-graphscope
iaaron
@antv/graphin-components
iaaron
@antv/g6-core
iaaron
banxuan
@antv/g6-plugin
banxuan
@antv/g6-pc
banxuan
@antv/g6-element
alex_zjt
@antv/g-shader-components
alex_zjt
@antv/g-plugin-html-renderer
alex_zjt
@antv/g-plugin-canvas-path-generator
newbyvector
@antv/xflow-core
newbyvector
@antv/x6-geometry
newbyvector
atool
@antv/g2-extension-plot
atool
@antv/event-emitter
atool
kasmine
@antv/dom-util
kasmine
@antv/adjust
kasmine
domdomegg
timeago-react
domdomegg
wjgogogo
jest-less-loader
wjgogogo
lvisei
@antv/l7plot-component
lvisei
moayuisuda
@antv/g2
moayuisuda
leondt1
@antv/ava
leondt1
← 모든 캠페인으로