6mile
@6mile.githax.com
Software Supply Chain Red Team. SourceCodeRED & SecureStack founder, dad, startup OG, snowboarder and hacker. Workin on GitHax tool in my spare time. github.com/6mile @eastsidemccarty from the bird site.
Heya @steipete.me can you do something about malicious skills in your ClawHub registry? Last night, one user published 200 malicious skills. I am tracking a dozen threat actors all publishing multiple malicious skills into this registry, and I've emailed you about all of them, but got crickets back
Some of the most popular packages on the OpenClaw official registry ClawHub are malicious @openclaw-x.bsky.social
FINALLY!!! github.com/microsoft/vs...
restore automatic task notification prompt, set automatic tasks to false by default by meganrogge · Pull Request #289947 · microsoft/vscode
fixes #287073 This restores the notification prompt that asks users to approve automatic tasks before they run, and changes the default behavior to be more secure. Default changed to off Permissio...
github.com
Ooooohh, this looks legit!
🤩 Honored to announce that I am part of the Review Committee, along with so many talented folks, for this new conference [Un]prompted, led by @gadievron! [Un]prompted is an AI security focused conference with several topics to continue to push the […] [Original post on infosec.exchange]
Another day, and another @hacker0x01.bsky.social "researcher" ganking people's AWS keys in a public NPM package (plugin-senna). 🤦♀️
We have a special episode of @absoluteappsec.bsky.social today with Paul McCarty @6mile.githax.com who will help us make sense of the last few weeks of npm news. So join Paul @sethlaw.bsky.social and @cktricky.bsky.social at 12 Noon ET here: www.youtube.com/watch?v=UM4F...
We knew it was coming, and now it's here: Dynamic payloads have been found in @npmjs.bsky.social packages. Ouch. 😦
The Safety research team has identified a new NPM based malware we are calling "Integrator-Filescrypt". This campaign uses a unique "cloaking" technique to hide from researchers and cloud providers. It's sneaky & very effective. Read more on our blog: www.getsafety.com/blog-posts/n...
Noice! I think this is the first time my work has been covered by @bleepingcomputer.com
A self-spreading package published on npm spams the registry by spawning new packages every every seven seconds, creating large volumes of junk.
I've identified a new worm affecting NPM. I'm calling it "IndonesianFoods" based on its internal dictionary. The intent is to generate assets on the Tea Protocol blockchain. It's dumb, but it's MASSIVE! Check the link 👉 sourcecodered.com/indonesianfo... @npmjs.bsky.social @github.com
Don't let AI write your payloads for you if you don't know what you're doing. Otherwise, you might end up publishing your API keys, environment variables, and identity to @npmjs.bsky.social
Want to sniff out private bug bounty programs? If you monitor OSV for new malicious packages, you'll get some great intel. Today's example: @npmjs.bsky.social user Paastha published 6 packages targeting @vercel.com. But wait, they don't have a BB program?! Or do they.... 😮💥
Tell me that @v0.dev has a bug bounty program without telling me they have a bug bounty program. #dependencyconfusion #maliciouspackage
I need to talk to someone in the @reversinglabs.com detection team. Anyone in my network got an intro?
I gave a talk at the FIRST CTI conference in Berlin earlier this year. Here's my presentation in its entirety. www.youtube.com/live/j23OubE...
YouTube
Share your videos with friends, family, and the world
youtube.com
Impressed with the Tenable One CSPM demo at the #Tenable #BlackHat booth. Blends vulnerability scanning with cloud security + ASPM features via IaC scanning and Git integrations. Worth checking if you're comparing cloud security solutions: bit.ly/4mbhg3e #BlackHat2025 #CloudSec
Tenable Cloud Security (CNAPP)
Reduce cloud risk and exposure from faulty configurations and entitlements with our cloud-native application protection platform (CNAPP), Tenable Cloud Security.
bit.ly
See me at 11 am today on the #DEFCON Creator State 4 (room 228). I'm super excited for this, and a big "thank you!" to the #AdversaryVillage team! #hackersummercamp @github.com
AI has written its first malicious package! I found an NPM package named @kodane/patch-manager that deploys a well-written persistent JavaScript crypto drainer. Here's the thing: I'm pretty sure Claude wrote it! Check out my post: getsafety.com/blog-posts/t... @anthropic.com @npmjs.bsky.social
Threat actor uses AI to create a better crypto wallet drainer
Safety’s malicious package detection identified a malicious package that appears to have been written by Claude AI
getsafety.com
I'm the first presentation for Adversary Village at @defcon.bsky.social. See me talk about open-source malware at 11 am on Saturday, August 9, in room 228 (creator stage 4)