TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Unpkg.com hacked?

20 点作者 benaiah大约 8 年前
I&#x27;ve checked on both my local machine and on a VPS I run, and the following URL is 302 redirecting to a malicious JS script which pops up a confirmation window and then redirects to ads:<p>SOURCE URL: https:&#x2F;&#x2F;unpkg.com&#x2F;react@latest&#x2F;dist&#x2F;react.js MALICIOUS REDIRECT: https:&#x2F;&#x2F;compliance-jessica.xyz&#x2F;a.php<p>This is the URL recommended for in-browser development use by https:&#x2F;&#x2F;facebook.github.io&#x2F;react&#x2F;docs&#x2F;installation.html<p>Can anyone else replicate this?

9 条评论

NuclearFishin大约 8 年前
Looks like there was indeed an issue with a bad nameserver update:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;unpkg&#x2F;status&#x2F;852660203275276289" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;unpkg&#x2F;status&#x2F;852660203275276289</a>
评论 #14129358 未加载
Erd0s6大约 8 年前
I was having this issue to but all good now. Should I be concerned about my computer being infected from this? Virus scans don&#x27;t find anything
davidjgraph大约 8 年前
unpkg are reporting this as fixed. <a href="https:&#x2F;&#x2F;twitter.com&#x2F;unpkg&#x2F;status&#x2F;852668919768694784" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;unpkg&#x2F;status&#x2F;852668919768694784</a>.<p>We got hit pretty hard for the 50 minutes or so the problem existed, Dropbox host their JS SDK lib on there...
davidkhess大约 8 年前
Seeing the same thing when trying to load Vue.<p>Tweet from them:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;unpkg&#x2F;status&#x2F;852655106562564098" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;unpkg&#x2F;status&#x2F;852655106562564098</a><p>&gt; We&#x27;re experiencing some issues and working on it. Will post updates here as soon as we know more.
评论 #14111510 未加载
CorySimmons大约 8 年前
We got close to trending on HackerNews yesterday when this happened.<p>Suddenly every visitor was reporting alert dialogs saying they had a virus and our votes dropped off a cliff.<p>Last time I ever go against my gut and semi-trust anything.
himlion大约 8 年前
Use subresource integrity and this would have affected you less. Still a non functioning site unfortunately.
DorianDevelops大约 8 年前
Sucks just got this on my github portfolio page that I put up a few days ago.<p>Any way to fix???
评论 #14111697 未加载
murftown大约 8 年前
Yes, I experienced the same thing.
svdpeijl大约 8 年前
here too - same thing.. this is ridiculous what a HUGE blunder on unpkg.com part