Amit Assaraf
@amitassaraf
Followers
198
Following
135
Media
1
Statuses
41
CEO @ Koi | https://t.co/XqKWqyVoGJ
Israel
Joined July 2014
https://t.co/pKpAp1lemu's launch couldn't have gone crazier ๐ซ the demand from organizations to protect their VSCode environments is insane (and rightfully so). Check out the aftermath of our research -
dex.koi.security
Quickly detect and eliminate risks in any software your teams rely on - extensions, packages, apps, and models.
1
0
6
RT @GetKoidex: ๐จ GlassWorm is back. Third wave. Microsoft's official VSCode Marketplace. Still live right now. We haven't even recovered fโฆ
0
1
0
๐จ ๐๐๐ฐ ๐ฐ๐๐ฏ๐ ๐จ๐ ๐๐ก๐๐ข-๐๐ฎ๐ฅ๐ฎ๐ ๐ฆ๐๐ฅ๐ฐ๐๐ซ๐ ๐๐๐ญ๐๐๐ญ๐๐, ๐ฐ๐ข๐ญ๐ก ๐จ๐ฏ๐๐ซ 800 ๐ฉ๐๐๐ค๐๐ ๐๐ฌ ๐๐จ๐ฆ๐ฉ๐ซ๐จ๐ฆ๐ข๐ฌ๐๐ We have been tracking a major resurgence of the Shai-Hulud malware campaign, now appearing as a new variant known asย Sha1-Hulud: The Second
2
3
7
๐จ Malicious VS Code extensions targeting Solidity developers! Two extensions found delivering a JavaScript dropper that fetches and runs a 5.6 MB Go binary (macOS ARM64) which steals crypto wallets, browser credentials and keychain passwords, then uploads the data as
2
1
7
๐จ New MCP Malware Discovered ๐จ Just days after uncovering the first malicious MCP server, weโve identified another: @lanyer640/mcp-runcommand-server. What looks like a handy tool to let your AI run system commands is actually a dual backdoor โ handing attackers a remote shell
1
2
8
๐จ ๐ช๐ฒ'๐๐ฒ ๐๐ป๐ฐ๐ผ๐๐ฒ๐ฟ๐ฒ๐ฑ ๐๐ต๐ฒ ๐ณ๐ถ๐ฟ๐๐ ๐บ๐ฎ๐น๐ถ๐ฐ๐ถ๐ผ๐๐ ๐ ๐๐ฃ ๐๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ถ๐ป ๐๐ต๐ฒ ๐๐ถ๐น๐ฑ. It was only a matter of time. The postmark-mcp npm package (1,500+ weekly downloads) has been backdoored since v1.0.16 - silently BCCing every email to the attacker's
16
152
439
Not every day we get a glimpse into the internal playbook of a cybercrime group. Today we exposed WhiteCobra, the threat actor that pawned @0xzak, with a wave of 24 malicious extensions in VSCode and Cursor's marketplaces.
1
2
11
๐จ Using Axiom for trading? A new Firefox extension is targeting you. It claims "100% local execution" Reality? It steals your credentials + wallet info, sends them to a remote server, and hides behind obfuscation and anti-detection. Always verify in Koidex ID: axiomtool
1
3
11
๐ฎ Some threat actors only care about their gaming life The Edge extension โVisual Robux Amount Changerโ doesnโt change your balance, it steals your .ROBLOSECURITY cookie and ships it off in Telegram (chat id: 1172948036). From there, the threat actor hijack your account, drain
2
2
9
"ืืชื ืกืืื AI, ืืืฉืืื ืฉืื ืืื ืืืืืง ืืช ืื ืืืืฉื ืืื ืืืฆืื ืืช ืคืจืื ืืืืืืจ ื-AWS ืืืืืืง ืืช ืื ืกืืืืช ืืขื ื" ื ืฉืืข ืืกืืื ืื? ืื ืื ืืื ืืื ืฉืงืืื ืกืืื ื-AI ืฉื ืืืืืื ืจืืข ืืคื ื ืฉืืืคืฅ ืืืืืืื ืืฉืชืืฉืื. ืฉืจืฉืืจ ืืกืืค"ืฉ
2
9
68
๐จ One overlooked flaw in Open VSX couldโve let attackers hijack dev machines via an extension supply chain attack. The zero-day has been patchedโbut it's clear: extensions are a new, massive supply chain risk. โก๏ธ Learn more: https://t.co/xCdJNeY2rV
#cybersecurity #sponsored
bleepingcomputer.com
Learn how one overlooked flaw in OpenVSX discovered by Koi Secureity could've let attackers hijack millions of dev machines via an extension supply chain attack. The zero-day threat's been patchedโ...
3
17
32
๐จ BREAKING: We uncovered "RedDirection" - 18 malicious browser extensions across Chrome & Edge that infected 2.3M+ users. Many were Google-verified & Microsoft-featured. Most are STILL LIVE in stores.
2
5
7
ืืืื ืคืจืกืื ื ืืืงืจ ืขื ืืขื 40 ืชืืกืคืื ืืืื ืืื ืืืจืงืืคืืืืก ืฉื ืคืืืจืคืืงืก ๐ฆ ืืชืืกืคืื ืืชืืืื ืืืืื ืคืืคืืืจืืื ืืื Metamask ืืื ืืจืืงื ืื ืืช ืืจื ืงื ืืงืจืืคืื ืฉื ืืงืืจืื ืืช.
๐จ Just uncovered: 40+ malicious Firefox extensions stealing crypto wallets by mimicking legit tools like MetaMask, Trust Wallet & Coinbase. Still active. Still spreading.
2
2
20
ืืฉืชืืฉืื ื-Cursor, Windsurf, ืื ืื Fork ืืืจ ืฉื VS Code? ืืืฉื ืฉื ืื ืืืืชื ืืฉืืคืื ืืคืืืขืืช ืงืจืืืืช ืฉืืคืฉืจื ืืชืืงืคืื ืืฉืืื ืืขืืจื ืืงืื ืฉืืื. ืืืืงืจ ืืืฉืจืืื @orenyomtov ืืืฆืืืช ืฉื Koi Security ืืืชืจื ืืืืฉื ืืืืจื ื-Open VSX, ืฉืืจืืช ืMarketplace ืื ืืฉืชืืฉืื ื-forks ืฉื VS Code. ืืืื ืืฉืจืฉืืจ ๐งต >>
3
2
12
๐จ Identified a malicious campaign using 5 extensions on VSCode Marketplace & OpenVSX with nearly 3M installs, targeting crypto devs. All share the same infra, executing PowerShell to fetch malicious script and drop a ScreenConnect for establishing full remote access. Extension
0
4
11
Dozens of fake wallet add-ons flood Firefox store to drain crypto - @billtoulas
https://t.co/vEyg1LHK5g
https://t.co/vEyg1LHK5g
bleepingcomputer.com
More thanย 40 fake extensions in Firefox's official add-ons store are impersonating popular cryptocurrency wallets from trusted providers to steal wallet credentials and sensitive data.
0
18
36
๐จ Just uncovered: 40+ malicious Firefox extensions stealing crypto wallets by mimicking legit tools like MetaMask, Trust Wallet & Coinbase. Still active. Still spreading.
1
4
10
๐จ One flaw in Open VSX gave attackers full control over millions of developer machines. They could've silently hijacked every VS Code extension. The supply chain risk? Massive. Here's how the breach almost happened โ and why it matters now โ
thehackernews.com
A critical vulnerability in Open VSX Registry could allow attackers to control VS Code extensions, threatening millions of developers.
0
12
36
ืืืืืื ื ืืฉืชืืฉืื ืฉื Cursor, Windsurf ืืขืื ืขืฉืจืืช IDEs ืืื ืืฉืืคืื ืืืฉื ืฉื ืื ืืืืืฉื ืฉืืฉืคื ื ืืืื. ืืจืื ืขืืจืื ืืงืื ืืคืืคืืืจืืื ืืืืชืจ ืืขืืื ืืืื ืืื Cursor, Windsurf ืื Google firebase studio ืืฉ ืืื ื ืืฉืืชืฃ ืืื - ืื ืืืื ื ืฉืขื ืื ืขื ืืืชื ืืจืงืืคืืืืก ืืฉื OpenVSX. ืืื ืื ืื ืืืจื ืขืืื ืืื ืืฉืชืื
1
5
42
๐จ Marketplace Takeover: Millions at Risk ๐จ Today, weโre lifting the embargo on one of the most critical supply-chain vulnerabilities weโve ever seen. Our team at Koi Security discovered a flaw in Open-VSX - the open extension marketplace used by over 8 million developers
1
4
10
ืืื ืชืืคืกืื ืงืืคืืื ืืืื ื ืืืจืงืืคืืืืก ืฉื VS Code? ืืชืืื ืืฉืคื ื ืงืืคืืื ืชืงืืคื ืฉืืฉืชืืื ืืืจืงืืคืืืืก ืฉื VS Code ืืื ืชืืืืช ืืืงืืืืจ. ืืืกืืจืช ืืงืืคืืื, ืืขื 10 ืชืืกืคืื ืืืื ืืื ืืชืืื ืืืื ืชืืืื ืืฉืคืช solidity ืื ืืชืืกืคืื ืืงืฉืืจืื ืืืื.
3
2
30