This commit is contained in:
2026-07-18 10:09:57 +09:00
parent 86cad348b4
commit 8f0e53766a
45 changed files with 6221 additions and 781 deletions
@@ -1,10 +1,10 @@
---
title: Open Source Package Supply Chain Attacks
created: 2026-07-01
updated: 2026-07-02
updated: 2026-07-16
type: concept
tags: [security, supply-chain, dev-tool, reliability]
sources: [raw/articles/checkmarx-operation-navy-ghost-pyrogram-supply-chain-2026.md, raw/articles/ladybird-maintainer-only-development-ai-pr-risk-2026.md]
sources: [raw/articles/checkmarx-operation-navy-ghost-pyrogram-supply-chain-2026.md, raw/articles/ladybird-maintainer-only-development-ai-pr-risk-2026.md, raw/articles/asyncapi-miasma-supply-chain-worm-2026.md]
confidence: medium
---
@@ -20,6 +20,8 @@ The useful pattern is that the malicious code targeted bot/server environments r
Ladybird の開発方針変更は、package registry ではなく open-source contribution path 側の trust model 変化を示す。Ladybird は AI tool によって「大きな patch を出す労力」が善意や長期関与の proxy ではなくなり、browser のように untrusted internet input を実行する project では、一つのよく隠れた脆弱性が深刻な結果を持つとして、public pull request を閉じ、maintainer だけが code を入れる方針へ移った。これは [[ci-cd-runtime-security]] や [[ai-agent-command-safety]] と同じく、AI が生成速度を上げたことで review capacity と responsibility boundary が希少資源になる例である。^[raw/articles/ladybird-maintainer-only-development-ai-pr-risk-2026.md]
AsyncAPI の npm package compromise は、package registry attack が `postinstall` だけでなく library の通常 `require()` / `import` path から発火しうることを示す。Flatt Security の解析では、`@asyncapi/[email protected](-alpha.1)` や `@asyncapi/[email protected]` などに Miasma worm が混入し、AWS、Kubernetes、Git、CI、npm token、環境変数を探索し、npm / PyPI / crates.io へ自己拡散する能力を持つ。さらに `.claude/settings.json`、`.gemini/settings.json`、`.cursor/rules/setup.mdc`、`.vscode/tasks.json` など AI coding tool 設定を書き換える永続化も含まれており、package supply chain と [[ai-agent-command-safety]] が同じ攻撃面へ収束している。^[raw/articles/asyncapi-miasma-supply-chain-worm-2026.md]
## Defensive implications
- Treat dependency names and maintainers as part of the threat model, especially for forks of popular libraries.
@@ -28,6 +30,7 @@ Ladybird の開発方針変更は、package registry ではなく open-source co
- For bot or agent services, rotate tokens and audit persistence if a malicious package may have run; the package may have accessed environment variables, sessions, files, or cloud credentials.
- Link package-ingest checks with [[ai-agent-command-safety]]: agents can install dependencies, run examples, or execute project scripts, so package manager operations are command-execution boundaries, not just setup steps.
- Treat generated-looking contribution volume as a review-capacity problem, not only a code-quality problem; projects may need narrower trusted committer paths when a disguised vulnerability is high impact.
- Add release-age quarantine / registry proxy checks where possible. AsyncAPI の事例では npm provenance があっても CI/CD 経由の悪性 publish は成立しており、provenance だけでは「正規 pipeline が乗っ取られた」場合を防げない。
## Open questions