Koidex
@GetKoidex
Followers
307
Following
91
Media
51
Statuses
84
Real-time intel on malicious extensions & packages across dev marketplaces. Governance + risk scoring for binary/non-binary software. By Koi.
Joined April 2025
๐จ We've uncovered a sophisticated supply chain attack targeting WhatsApp developers.ย The npm package "lotusbail" steal your WhatsApp credentials, intercept all messages, exfiltrate contacts and media, then encrypt and transmit everything to attacker servers. Our analysis shows
0
1
6
๐จ Security Alert! We found a Chrome extension called "KeeProx" that claims to be a password manager. The irony? It stores your passwords using a hash so weak it could be cracked faster than you can type "password123." A password manager that makes your passwords less secure. You
0
1
3
"My shared typescript utilities" - sure, buddy. We just caught dozy on npm doing anything but utility work: ๐ Heavy obfuscation + anti-tampering ๐ DevTools detection (window size, debugger timing, F12 blocking) ๐ซ Right-click disabled โช๏ธ Redirects to google[.]com/<random> when
0
0
8
A Bitcoin theme and an AI assistant walk into VS Code's marketplaceโฆ Both uploaded today. Same publisher. Both execute hidden scripts on install. The payload? An infostealer masquerading as Lightshot. It grabs: ๐ธ Screenshots ๐ Clipboard ๐ถ WiFi passwords ๐ช Browser sessions
1
0
10
๐๐จ Christmas came early this yearโฆ for threat actors! Weโre tracking 300+ malicious npm packages flooding the registry in the last 24 hours, all following the pattern: elf-stats-<christmas_word>-<christmas_word>-<number> These naughty packages abuse post/pre-install hooks to
0
1
6
Malicious Extension Detected! ๐จ ๐ We uncovered a malicious extension named โไผ ๅฅ่ๆฌ่ฏญ่จๆฏๆ (Legend Script Language Support)โ across VSCode and OpenVSX marketplaces Despite claiming to enhance coding with syntax highlighting, snippets, and theme support - itโs actually
0
3
11
Everyone: โJust scan code with AI, itโll catch all the malware.โ Malware authors: hold my npm package. We just caught a package that: ๐น steals your NODE_ENV ๐น exfiltrates it to a Pipedream /leak endpoint ๐น racked up ~17k downloads over 2 years The wild part? It embeds an
1
2
9
๐จ GlassWorm is back. Third wave. Microsoft's official VSCode Marketplace. Still live right now. We haven't even recovered from Shai-Hulud's second wave hitting npm this week, and now GlassWorm is back. Six weeks ago, we disclosed GlassWorm - a worm targeting VS Code
0
2
7
๐จ Chrome extension "Health Reminder" reminds you to drink water while it drinks ALL your browsing data. This "wellness tool" is about as healthy as a deep-fried cigarette - it logs every site you visit, tracks keywords in your URLs, exfiltrates everything to a remote server, and
1
0
6
๐๐ Follow our updating incident page in the first comment for a deeper technical breakdown. https://t.co/F5I2fVPPzM
koi.ai
A new wave of the Shai-Hulud malware is compromising hundreds of npm packages and destroying user home directories. Get live updates and mitigation steps.
0
2
4
๐จ ๐๐๐ฐ ๐ฐ๐๐ฏ๐ ๐จ๐ ๐๐ก๐๐ข-๐๐ฎ๐ฅ๐ฎ๐ ๐ฆ๐๐ฅ๐ฐ๐๐ซ๐ ๐๐๐ญ๐๐๐ญ๐๐, ๐ฐ๐ข๐ญ๐ก ๐จ๐ฏ๐๐ซ 800 ๐ฉ๐๐๐ค๐๐ ๐๐ฌ ๐๐จ๐ฆ๐ฉ๐ซ๐จ๐ฆ๐ข๐ฌ๐๐ We have been tracking a major resurgence of the Shai-Hulud malware campaign, now appearing as a new variant known asย Sha1-Hulud: The Second
2
3
7
Weโve found another malicious extension from the same campaign - Nomic-Foundation.hardhat-vscode. It drops the same Go-based stealer that exfiltrates wallets, browser creds, and keychain data to function.undefined21[.]com.
0
0
1
๐จ Malicious VS Code extensions targeting Solidity developers! Two extensions found delivering a JavaScript dropper that fetches and runs a 5.6 MB Go binary (macOS ARM64) which steals crypto wallets, browser credentials and keychain passwords, then uploads the data as
2
1
7
๐จ GlassWorm strikes again 3 new infected extensions on open-vsx detected using the same invisible Unicode stealth technique: ai-driven-dev.ai-driven-dev yasuyuky.transient-emacs adhamu.history-in-sublime-merge ~10K additional infections. Same attack pattern: malicious code
1
1
5