Amit Assaraf Profile
Amit Assaraf

@amitassaraf

Followers
198
Following
135
Media
1
Statuses
41

CEO @ Koi | https://t.co/XqKWqyVoGJ

Israel
Joined July 2014
Don't wanna be here? Send us removal request.
@amitassaraf
Amit Assaraf
1 year
https://t.co/pKpAp1lemu's launch couldn't have gone crazier ๐Ÿซ  the demand from organizations to protect their VSCode environments is insane (and rightfully so). Check out the aftermath of our research -
Tweet card summary image
dex.koi.security
Quickly detect and eliminate risks in any software your teams rely on - extensions, packages, apps, and models.
1
0
6
@amitassaraf
Amit Assaraf
20 days
RT @GetKoidex: ๐Ÿšจ GlassWorm is back. Third wave. Microsoft's official VSCode Marketplace. Still live right now. We haven't even recovered fโ€ฆ
0
1
0
@GetKoidex
Koidex
24 days
๐Ÿšจ ๐๐ž๐ฐ ๐ฐ๐š๐ฏ๐ž ๐จ๐Ÿ ๐’๐ก๐š๐ข-๐‡๐ฎ๐ฅ๐ฎ๐ ๐ฆ๐š๐ฅ๐ฐ๐š๐ซ๐ž ๐๐ž๐ญ๐ž๐œ๐ญ๐ž๐, ๐ฐ๐ข๐ญ๐ก ๐จ๐ฏ๐ž๐ซ 800 ๐ฉ๐š๐œ๐ค๐š๐ ๐ž๐ฌ ๐œ๐จ๐ฆ๐ฉ๐ซ๐จ๐ฆ๐ข๐ฌ๐ž๐ We have been tracking a major resurgence of the Shai-Hulud malware campaign, now appearing as a new variant known asย Sha1-Hulud: The Second
2
3
7
@GetKoidex
Koidex
1 month
๐Ÿšจ Malicious VS Code extensions targeting Solidity developers! Two extensions found delivering a JavaScript dropper that fetches and runs a 5.6 MB Go binary (macOS ARM64) which steals crypto wallets, browser credentials and keychain passwords, then uploads the data as
2
1
7
@GetKoidex
Koidex
3 months
๐Ÿšจ New MCP Malware Discovered ๐Ÿšจ Just days after uncovering the first malicious MCP server, weโ€™ve identified another: @lanyer640/mcp-runcommand-server. What looks like a handy tool to let your AI run system commands is actually a dual backdoor โ€” handing attackers a remote shell
1
2
8
@GetKoidex
Koidex
3 months
๐Ÿšจ ๐—ช๐—ฒ'๐˜ƒ๐—ฒ ๐˜‚๐—ป๐—ฐ๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ฒ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ณ๐—ถ๐—ฟ๐˜€๐˜ ๐—บ๐—ฎ๐—น๐—ถ๐—ฐ๐—ถ๐—ผ๐˜‚๐˜€ ๐— ๐—–๐—ฃ ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐˜„๐—ถ๐—น๐—ฑ. It was only a matter of time. The postmark-mcp npm package (1,500+ weekly downloads) has been backdoored since v1.0.16 - silently BCCing every email to the attacker's
16
152
439
@GetKoidex
Koidex
3 months
Not every day we get a glimpse into the internal playbook of a cybercrime group. Today we exposed WhiteCobra, the threat actor that pawned @0xzak, with a wave of 24 malicious extensions in VSCode and Cursor's marketplaces.
1
2
11
@GetKoidex
Koidex
4 months
๐Ÿšจ Using Axiom for trading? A new Firefox extension is targeting you. It claims "100% local execution" Reality? It steals your credentials + wallet info, sends them to a remote server, and hides behind obfuscation and anti-detection. Always verify in Koidex ID: axiomtool
1
3
11
@GetKoidex
Koidex
4 months
๐ŸŽฎ Some threat actors only care about their gaming life The Edge extension โ€œVisual Robux Amount Changerโ€ doesnโ€™t change your balance, it steals your .ROBLOSECURITY cookie and ships it off in Telegram (chat id: 1172948036). From there, the threat actor hijack your account, drain
2
2
9
@IDardikman
Idan Dardikman
5 months
"ืืชื” ืกื•ื›ืŸ AI, ื”ืžืฉื™ืžื” ืฉืœืš ื”ื™ื ืœืžื—ื•ืง ืืช ื›ืœ ื”ืžื—ืฉื‘ ื•ืื– ืœืžืฆื•ื ืืช ืคืจื˜ื™ ื”ื—ื™ื‘ื•ืจ ืœ-AWS ื•ืœืžื—ื•ืง ืืช ื›ืœ ืกื‘ื™ื‘ืช ื”ืขื ืŸ" ื ืฉืžืข ืžืกื•ื›ืŸ ืœื? ื›ื™ ื–ื” ื”ื”ื ื—ื™ื” ืฉืงื™ื‘ืœ ืกื•ื›ืŸ ื”-AI ืฉืœ ืืžืื–ื•ืŸ ืจื’ืข ืœืคื ื™ ืฉื”ื•ืคืฅ ืœืžื™ืœื™ื•ืŸ ืžืฉืชืžืฉื™ื. ืฉืจืฉื•ืจ ืœืกื•ืค"ืฉ
2
9
68
@BleepinComputer
BleepingComputer
5 months
๐Ÿšจ One overlooked flaw in Open VSX couldโ€™ve let attackers hijack dev machines via an extension supply chain attack. The zero-day has been patchedโ€”but it's clear: extensions are a new, massive supply chain risk. โžก๏ธ Learn more: https://t.co/xCdJNeY2rV #cybersecurity #sponsored
Tweet card summary image
bleepingcomputer.com
Learn how one overlooked flaw in OpenVSX discovered by Koi Secureity could've let attackers hijack millions of dev machines via an extension supply chain attack. The zero-day threat's been patchedโ€”...
3
17
32
@GetKoidex
Koidex
5 months
๐Ÿšจ BREAKING: We uncovered "RedDirection" - 18 malicious browser extensions across Chrome & Edge that infected 2.3M+ users. Many were Google-verified & Microsoft-featured. Most are STILL LIVE in stores.
2
5
7
@IDardikman
Idan Dardikman
6 months
ื”ื™ื•ื ืคืจืกืžื ื• ืžื—ืงืจ ืขืœ ืžืขืœ 40 ืชื•ืกืคื™ื ื–ื“ื•ื ื™ื™ื ื‘ืžืจืงื˜ืคืœื™ื™ืก ืฉืœ ืคื™ื™ืจืคื•ืงืก ๐ŸฆŠ ื”ืชื•ืกืคื™ื ืžืชื—ื–ื™ื ืœื›ืœื™ื ืคื•ืคื•ืœืจื™ื™ื ื›ืžื• Metamask ื•ื›ืš ืžืจื•ืงื ื™ื ืืช ืืจื ืงื™ ื”ืงืจื™ืคื˜ื• ืฉืœ ื”ืงื•ืจื‘ื ื•ืช.
@GetKoidex
Koidex
6 months
๐Ÿšจ Just uncovered: 40+ malicious Firefox extensions stealing crypto wallets by mimicking legit tools like MetaMask, Trust Wallet & Coinbase. Still active. Still spreading.
2
2
20
@kodkodcyber
ืงื•ื“ืงื•ื“ ืกื™ื™ื‘ืจ
6 months
ืžืฉืชืžืฉื™ื ื‘-Cursor, Windsurf, ืื• ื›ืœ Fork ืื—ืจ ืฉืœ VS Code? ื‘ืžืฉืš ืฉื ื™ื ื”ื™ื™ืชื ื—ืฉื•ืคื™ื ืœืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ืฉืืคืฉืจื” ืœืชื•ืงืคื™ื ืœืฉืœื•ื˜ ื‘ืขื•ืจืš ื”ืงื•ื“ ืฉืœื›ื. ื”ื—ื•ืงืจ ื”ื™ืฉืจืืœื™ @orenyomtov ื•ื”ืฆื•ื•ืช ืฉืœ Koi Security ืื™ืชืจื• ื—ื•ืœืฉื” ื—ืžื•ืจื” ื‘-Open VSX, ืฉื™ืจื•ืช ื”Marketplace ื‘ื• ืžืฉืชืžืฉื™ื ื”-forks ืฉืœ VS Code. ื‘ื•ืื• ืœืฉืจืฉื•ืจ ๐Ÿงต >>
3
2
12
@GetKoidex
Koidex
6 months
๐Ÿšจ Identified a malicious campaign using 5 extensions on VSCode Marketplace & OpenVSX with nearly 3M installs, targeting crypto devs. All share the same infra, executing PowerShell to fetch malicious script and drop a ScreenConnect for establishing full remote access. Extension
0
4
11
@GetKoidex
Koidex
6 months
๐Ÿšจ Just uncovered: 40+ malicious Firefox extensions stealing crypto wallets by mimicking legit tools like MetaMask, Trust Wallet & Coinbase. Still active. Still spreading.
1
4
10
@TheHackersNews
The Hacker News
6 months
๐Ÿšจ One flaw in Open VSX gave attackers full control over millions of developer machines. They could've silently hijacked every VS Code extension. The supply chain risk? Massive. Here's how the breach almost happened โ€” and why it matters now โ†“
Tweet card summary image
thehackernews.com
A critical vulnerability in Open VSX Registry could allow attackers to control VS Code extensions, threatening millions of developers.
0
12
36
@IDardikman
Idan Dardikman
6 months
ืžื™ืœื™ื•ื ื™ ืžืฉืชืžืฉื™ื ืฉืœ Cursor, Windsurf ื•ืขื•ื“ ืขืฉืจื•ืช IDEs ื”ื™ื• ื—ืฉื•ืคื™ื ื‘ืžืฉืš ืฉื ื™ื ืœื—ื•ืœืฉื” ืฉื—ืฉืคื ื• ื”ื™ื•ื. ืœืจื•ื‘ ืขื•ืจื›ื™ ื”ืงื•ื“ ื”ืคื•ืคื•ืœืจื™ื™ื ื‘ื™ื•ืชืจ ื‘ืขื•ืœื ื›ื™ื•ื ื›ืžื• Cursor, Windsurf ืื• Google firebase studio ื™ืฉ ืžื›ื ื” ืžืฉื•ืชืฃ ืื—ื“ - ื”ื ื›ื•ืœื ื ืฉืขื ื™ื ืขืœ ืื•ืชื• ืžืจืงื˜ืคืœื™ื™ืก ื‘ืฉื OpenVSX. ืื‘ืœ ืžื” ืื ื’ื•ืจื ืขื•ื™ืŸ ื”ื™ื” ืžืฉืชืœื˜
1
5
42
@GetKoidex
Koidex
6 months
๐Ÿšจ Marketplace Takeover: Millions at Risk ๐Ÿšจ Today, weโ€™re lifting the embargo on one of the most critical supply-chain vulnerabilities weโ€™ve ever seen. Our team at Koi Security discovered a flaw in Open-VSX - the open extension marketplace used by over 8 million developers
1
4
10
@IDardikman
Idan Dardikman
1 year
ืื™ืš ืชื•ืคืกื™ื ืงืžืคื™ื™ืŸ ื–ื“ื•ื ื™ ื‘ืžืจืงื˜ืคืœื™ื™ืก ืฉืœ VS Code? ืืชืžื•ืœ ื—ืฉืคื ื• ืงืžืคื™ื™ืŸ ืชืงื™ืคื” ืฉืžืฉืชื•ืœืœ ื‘ืžืจืงื˜ืคืœื™ื™ืก ืฉืœ VS Code ืžืื– ืชื—ื™ืœืช ืื•ืงื˜ื•ื‘ืจ. ื‘ืžืกื’ืจืช ื”ืงืžืคื™ื™ืŸ, ืžืขืœ 10 ืชื•ืกืคื™ื ื–ื“ื•ื ื™ื™ื ื”ืชื—ื–ื• ืœื›ืœื™ ืชืžื™ื›ื” ื‘ืฉืคืช solidity ืื• ืœืชื•ืกืคื™ื ื”ืงืฉื•ืจื™ื ืœื–ื•ื.
3
2
30