Eslam Salem

@netcodex.bsky.social

Manager, security research @ Datadog | he/him | Chess lover | Blackhat speaker | ex Sqreen.io, Shieldfy.io | my website: https://eslam.io

I'm in love with claude code. The way it handles code writing and automates bash tasks is amazing and so convenient to me. if you are an experienced developer, know what you are doing, the tasks that usually take Weeks. You will be able to do it in Hours 🤯🤯 #claudecode #ai

🚨 The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions! Deep dive analysis in this obfuscated campaign including (PowerShell & VBS scripts, PE malware, Malicious browser extensions even stegomalware) Enjoy reading securitylabs.datadoghq.com/articles/mut...

The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs

Analysis of a threat actor campaign targeting Solidity developers via three malicious VS Code extensions

securitylabs.datadoghq.com

I don't like threat actors attribution that much because in most cases it's wrong and so easily to be forged. We still should cluster campaigns but there is no "high confidence" attribution IMHO.