티스토리 뷰
Your Security Program Could Be a Hacking Tool? Here's an Easy Explanation of Supply Chain Attacks That Even Developers Fell For
실더 2026. 5. 26. 21:00
Wait, the security tool I trusted became a hacking tool?
You know that program your IT team at work sends you saying "Please install this"? You obviously trust it because they say it's a security tool, so you install it without thinking. But what if that installation file itself was already hacked? Just thinking about it gives you chills, right?
Well, that's exactly what happened this time. There's this program called Trivy, which is originally a tool that developers use to check if their software has security vulnerabilities. In simple terms, it's like "an antivirus program but for developers to check code security." But this security checker itself got breached by attackers.
The attackers secretly broke into the system that distributes Trivy and uploaded a malicious version as if it were the real thing. So from a developer's perspective, the file they got from the "official website" was actually a hacking tool. Honestly, even experts would have a hard time spotting this right away.
So what exactly got stolen and how much?
The software affected by this incident is honestly massive. Besides Trivy, another development tool called TanStack was also compromised, and through these two tools, a whole chain of other software got infected one after another. It was like dominoes falling.
| Affected Area | Scale |
|---|---|
| npm packages (JavaScript development tools collection) | 64+ packages |
| TanStack packages (UI development tools) | 42 packages, 84 versions |
| PyPI packages (Python development tools collection) | Including litellm, telnyx, etc. |
| VS Code extensions | Multiple affected |
| Severity level (CVSS score, out of 10) | 9.4 / 9.6 points |
If the CVSS score is in the 9s, it's basically the highest danger category. For reference, a score of 10 means "it's the kind of thing that would flip the entire world upside down." So 9.4 and 9.6 are essentially at that level.
And when this malicious file gets installed, it secretly plants pgmon or sysmon backdoors inside your computer. Through these backdoors, attackers stay in regular contact with their server (C2 server) and continuously steal information.
The list of leaked information is absolutely massive too. Cloud authentication credentials for AWS, GCP, and Azure, SSH keys (server login passwords), cryptocurrency wallet info for Bitcoin and Ethereum, database passwords, and even .env files (development environment configuration files) were all stolen. Seriously, there's nothing left.
I'm not a developer, but am I at risk too?
You might be thinking, "Well, I'm not a developer, so I should be fine, right?" But actually, that's not necessarily true. Even if you don't directly use these tools, you can still be indirectly affected.
Let me give you an example. You know those internal company systems, online shopping malls, and app services you use every day? If the development team that built them was using one of these compromised tools, then their server information got stolen. And if my personal info or payment details are on that server? Yeah, I'm connected to the problem.
Also, these days a lot of people who work in IT at companies use a program called VS Code (Visual Studio Code). Since VS Code extensions were also affected in this incident, even if you're not a developer, if you use this program, you should probably check it out.
Here's what you can do right now that actually makes a difference
Don't panic. There are definitely things you can do. Just following these three steps will make a huge difference.
~/.local/share/pgmon/ or ~/.config/sysmon/ directories.Frequently Asked Questions
A. If you're not using them directly, your direct risk is low. But the development team that created the services or company systems you use might have been using these tools. If their server info gets leaked, your information could indirectly be at risk too. That's why setting up two-factor authentication on important accounts is the best preventive measure.
A. With supply chain attacks like this one, the official distribution system itself can be breached, so you can get infected even through official channels. That's why companies and development teams shouldn't rely solely on automatic software updates—it's good to also verify hash values (file unique authentication numbers) and subscribe to official security announcements. For regular users, just not installing extensions from unclear sources already makes you much safer.
This incident might feel like a story from far away, but honestly, it's way more connected to our daily lives than you'd think. The apps you use every day, your company systems, and your payment info are all connected through someone's development environment somewhere. I'm not saying this to scare you—but by knowing this kind of thing happens and just taking basic precautions, you'll be much safer. If you know any developer friends, it might be good to share this with them! 😊
#SupplyChainAttack #SecurityNews #Trivy #TanStack #HackingAlert #KISA #DeveloperSecurity #CyberSecurity
'Security News(Eng)' 카테고리의 다른 글
- Total
- Today
- Yesterday
- infosecurity
- cve
- PrivacyProtection
- supplychainattack
- Malware
- 악성코드
- 사이버보안
- 2단계인증
- 정보보안
- 보안뉴스
- cybersecurity
- HackingPrevention
- 취약점
- 보안상식
- 금취분평
- DataPrivacy
- HackingAlert
- SecurityTips
- 해킹주의
- 샤이니헌터스
- 보안꿀팁
- 전자금융기반시설
- 공급망공격
- 랜섬웨어
- 전자금융기반시설취약점분석평가
- securitynews
- 개인정보유출
- 스마트폰보안
- 개인정보보호
- 해킹예방
| 일 | 월 | 화 | 수 | 목 | 금 | 토 |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | 6 | |
| 7 | 8 | 9 | 10 | 11 | 12 | 13 |
| 14 | 15 | 16 | 17 | 18 | 19 | 20 |
| 21 | 22 | 23 | 24 | 25 | 26 | 27 |
| 28 | 29 | 30 |