Interesting backdoor in an npm package. Analyzing the timezone in git commit metadata shows this is likely a compromised maintainer account
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor securitylabs.datadoghq.com/articles/not...
Christophe Tafani-Dereeper
@christophetd.fr
Cloud and container security • Security research and open source at Datadog 🇨🇭🇫🇷 https://christophetd.fr
Interesting backdoor in an npm package. Analyzing the timezone in git commit metadata shows this is likely a compromised maintainer account
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor securitylabs.datadoghq.com/articles/not...
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond securitylabs.datadoghq.com/articles/beh...
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond | Datadog Security Labs
Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.
securitylabs.datadoghq.com
My Claude credits today, seeing me try Fable 5
Melting Chocolate Bunny with Googly Eyes
Alt: melting claude credits
static.klipy.com
Freshly out on the Datadog Engineering blog! From single pull requests to full software packages: Detecting malicious code at scale www.datadoghq.com/blog/enginee...
Scaling malicious code detection from pull requests to the software supply chain | Datadog
Datadog scaled malicious code detection from pull requests to dependency packages using stacked LLM evaluations and agentic investigation.
datadoghq.com
I wrote up an analysis of the Axios compromise: securitylabs.datadoghq.com/articles/axi... Crazy how while researchers were filing issues to report the compromise, the attacker was deleting them in real time using the maintainer's GitHub access!
Yesterday, a threat actor compromised 2 versions of the LiteLLM Python package (40k stars, 3M+ weekly downloads). The malicious versions had 120k downloads before being taken down Full write-up: securitylabs.datadoghq.com/articles/lit... Timeline (h/t @ramimac.me): ramimac.me/trivy-teampcp/
LiteLLM compromised on PyPI: Tracing the March 2026 TeamPCP supply chain campaign securitylabs.datadoghq.com/articles/lit...
When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos www.datadoghq.com/blog/enginee...
When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos | Datadog
Learn how Datadog detected and resolved issues from hackerbot-claw, an AI-powered automated attack campaign.
datadoghq.com
Fresh and active AWS phishing campaign with 3 main domains: cloud-recovery[.]us cloud-recovery[.]net aws[.]cloud-recovery[.]us ... with hands-on-keyboard activity 20 minutes after credentials are submitted
Behind the console: Active phishing campaign targeting AWS console credentials securitylabs.datadoghq.com/articles/beh...
#Podcast #Cybersécurité Épisode #534 consacré au ver "Shai-Hulud", avec @christophetd.fr www.nolimitsecu.fr/shai-hulud/
Shai-Hulud - NoLimitSecu
Episode #534 consacré à « Shai-Hulud » Avec Christophe Tafani-Dereeper Références : Shai-Hulud: https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/ https://github.com/DataDog/indicat...
nolimitsecu.fr
I asked Claude (Opus 4.6) and Codex (GPT-5.3) to each generate a simple LinkedList implementation in Java. Then I asked Claude to pick the better one. No hesitation: "The Codex version is better" 🤔 gist.github.com/christophetd...
If you're using VSCode or Cursor, this is a pretty solid extension to have in your toolbox!
IDE-SHEPHERD is a new open source project to identify malicious VSCode and Cursor extensions at runtime Announcement: securitylabs.datadoghq.com/articles/ide... GitHub: github.com/DataDog/IDE-...
Decoding the GitHub recommendations for npm maintainers securitylabs.datadoghq.com/articles/dec... by @phrawzty.com
Decoding the GitHub recommendations for npm maintainers | Datadog Security Labs
This blog post explores the rationale and implementation behind GitHub's security recommendations for npm maintainers following numerous high-profile supply-chain incidents. It details how hardening p...
securitylabs.datadoghq.com
Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users securitylabs.datadoghq.com/articles/inv...
CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js securitylabs.datadoghq.com/articles/cve...
A few days ago, a new piece of malware started spreading in npm, compromising and backdooring hundreds of legitimate npm packages and GitHub users. Read the analysis from our security research team: securitylabs.datadoghq.com/articles/sha...
If you're in cloud security, do have a look at this piece of research I've been working on! Feedback / thoughts welcome
Our State of Cloud Security 2025 study is out! www.datadoghq.com/state-of-clo... • On AWS, 40% of organizations leverage data perimeters • 11% of Google Cloud GKE and 23% of Google Cloud VMs are overprivileged • On Azure, 1.3% of storage containers are public, 58% proactively block public access
The EU is advancing legislation requiring all messaging platforms to scan private messages, even in encrypted apps like Signal/WhatsApp/Telegram. 600+ security researchers oppose ChatControl for being technically flawed. Learn more about it 👉 metalhearf.fr/posts/chatco... #ChatControl #privacy
ChatControl wants to scan all your private messages
The EU is pushing legislation that would scan all our private messages, even in encrypted apps.
metalhearf.fr
If you're into cloud security, fwd:cloudsec Europe is now live. Schedule: fwdcloudsec.org/conference/e...
Schedule | fwd:cloudsec Europe 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
fwdcloudsec.org
fwd:cloudsec Europe is now live from Berlin! Watch the livestream here: youtube.com/live/-a9Ts7A...
I did a bit more looking into the upcoming bitnami deprecation. The images are still getting millions of pulls a week, so depending on exactly what tags vanish next week, there could be a lot of broken deploys on the 28th! raesene.github.io/blog/2025/08...
Bitnami Deprecation
raesene.github.io
@micahflee.com thank you for the amazing and inspiring defcon talk
I arbitrarily picked a list of 50 talks I'm most excited about that are happening next week at DEF CON / Black Hat / BSides LV / The Diana Initiative. I'll also add recordings/slides to this list when they become available!
Datadog guide to Hacker Summer Camp 2025, amd the top 50 talks we're excited about securitylabs.datadoghq.com/articles/hac...
Getting ready for DEF CON next week! ✅ Slides ✅ Demos ✅ Custom shirt designed for the occasion
Looks like the maintainer of a number of highly-popular npm packages was phished through npnjs[.]com, and his access used to publish malicious versions of their packages x.com/JounQin/stat... www.linkedin.com/feed/update/... github.com/prettier/esl...
Stratus Red Team AWS attack techniques are now mapped to the Threat Technique Catalog for AWS Stratus Red Team AWS attack techniques: stratus-red-team.cloud/attack-techn... Threat Technique Catalog by AWS: aws-samples.github.io/threat-techn...
The MCP spec has been updated to include security best practices • Confused deputy • Token passthrough • Session hijacking modelcontextprotocol.io/specificatio...
Security Best Practices - Model Context Protocol
modelcontextprotocol.io
👀
"Tales from the cloud trenches: The Attacker doth persist too much, methinks" securitylabs.datadoghq.com/articles/tal... New tactics observed include: • Persistence-as-a-service with an external facing API Gateway • Persistence through AWS SSO • ConsoleLogin events from Telegram IP addresses