GetKoidex Profile Banner
Koidex Profile
Koidex

@GetKoidex

Followers
307
Following
91
Media
51
Statuses
84

Real-time intel on malicious extensions & packages across dev marketplaces. Governance + risk scoring for binary/non-binary software. By Koi.

Joined April 2025
Don't wanna be here? Send us removal request.
@GetKoidex
Koidex
18 hours
๐Ÿšจ We've uncovered a sophisticated supply chain attack targeting WhatsApp developers.ย  The npm package "lotusbail" steal your WhatsApp credentials, intercept all messages, exfiltrate contacts and media, then encrypt and transmit everything to attacker servers. Our analysis shows
0
1
6
@GetKoidex
Koidex
10 days
๐Ÿšจ Security Alert! We found a Chrome extension called "KeeProx" that claims to be a password manager. The irony? It stores your passwords using a hash so weak it could be cracked faster than you can type "password123." A password manager that makes your passwords less secure. You
0
1
3
@GetKoidex
Koidex
14 days
"My shared typescript utilities" - sure, buddy. We just caught dozy on npm doing anything but utility work: ๐Ÿ”’ Heavy obfuscation + anti-tampering ๐Ÿ” DevTools detection (window size, debugger timing, F12 blocking) ๐Ÿšซ Right-click disabled โ†ช๏ธ Redirects to google[.]com/<random> when
0
0
8
@GetKoidex
Koidex
14 days
A Bitcoin theme and an AI assistant walk into VS Code's marketplaceโ€ฆ Both uploaded today. Same publisher. Both execute hidden scripts on install. The payload? An infostealer masquerading as Lightshot. It grabs: ๐Ÿ“ธ Screenshots ๐Ÿ“‹ Clipboard ๐Ÿ“ถ WiFi passwords ๐Ÿช Browser sessions
1
0
10
@GetKoidex
Koidex
15 days
๐ŸŽ„๐Ÿšจ Christmas came early this yearโ€ฆ for threat actors! Weโ€™re tracking 300+ malicious npm packages flooding the registry in the last 24 hours, all following the pattern: elf-stats-<christmas_word>-<christmas_word>-<number> These naughty packages abuse post/pre-install hooks to
0
1
6
@GetKoidex
Koidex
19 days
Malicious Extension Detected! ๐Ÿšจ ๐Ÿ”Ž We uncovered a malicious extension named โ€œไผ ๅฅ‡่„šๆœฌ่ฏญ่จ€ๆ”ฏๆŒ (Legend Script Language Support)โ€ across VSCode and OpenVSX marketplaces Despite claiming to enhance coding with syntax highlighting, snippets, and theme support - itโ€™s actually
0
3
11
@GetKoidex
Koidex
21 days
Everyone: โ€œJust scan code with AI, itโ€™ll catch all the malware.โ€ Malware authors: hold my npm package. We just caught a package that: ๐Ÿ”น steals your NODE_ENV ๐Ÿ”น exfiltrates it to a Pipedream /leak endpoint ๐Ÿ”น racked up ~17k downloads over 2 years The wild part? It embeds an
1
2
9
@GetKoidex
Koidex
22 days
๐Ÿšจ GlassWorm is back. Third wave. Microsoft's official VSCode Marketplace. Still live right now. We haven't even recovered from Shai-Hulud's second wave hitting npm this week, and now GlassWorm is back. Six weeks ago, we disclosed GlassWorm - a worm targeting VS Code
0
2
7
@GetKoidex
Koidex
23 days
๐Ÿšจ Chrome extension "Health Reminder" reminds you to drink water while it drinks ALL your browsing data. This "wellness tool" is about as healthy as a deep-fried cigarette - it logs every site you visit, tracks keywords in your URLs, exfiltrates everything to a remote server, and
1
0
6
@GetKoidex
Koidex
25 days
๐Ÿšจ ๐๐ž๐ฐ ๐ฐ๐š๐ฏ๐ž ๐จ๐Ÿ ๐’๐ก๐š๐ข-๐‡๐ฎ๐ฅ๐ฎ๐ ๐ฆ๐š๐ฅ๐ฐ๐š๐ซ๐ž ๐๐ž๐ญ๐ž๐œ๐ญ๐ž๐, ๐ฐ๐ข๐ญ๐ก ๐จ๐ฏ๐ž๐ซ 800 ๐ฉ๐š๐œ๐ค๐š๐ ๐ž๐ฌ ๐œ๐จ๐ฆ๐ฉ๐ซ๐จ๐ฆ๐ข๐ฌ๐ž๐ We have been tracking a major resurgence of the Shai-Hulud malware campaign, now appearing as a new variant known asย Sha1-Hulud: The Second
2
3
7
@GetKoidex
Koidex
1 month
Weโ€™ve found another malicious extension from the same campaign - Nomic-Foundation.hardhat-vscode. It drops the same Go-based stealer that exfiltrates wallets, browser creds, and keychain data to function.undefined21[.]com.
0
0
1
@GetKoidex
Koidex
1 month
๐Ÿšจ Malicious VS Code extensions targeting Solidity developers! Two extensions found delivering a JavaScript dropper that fetches and runs a 5.6 MB Go binary (macOS ARM64) which steals crypto wallets, browser credentials and keychain passwords, then uploads the data as
2
1
7
@GetKoidex
Koidex
1 month
๐Ÿšจ GlassWorm strikes again 3 new infected extensions on open-vsx detected using the same invisible Unicode stealth technique: ai-driven-dev.ai-driven-dev yasuyuky.transient-emacs adhamu.history-in-sublime-merge ~10K additional infections. Same attack pattern: malicious code
1
1
5