Tomislav Pericin
@ap0x
Followers
2K
Following
4K
Media
21
Statuses
1K
CSA at ReversingLabs LLC. Designs file analysis platforms, engines and reverse engineering tools for fun. Something about unpacking and PE file format.
Republic of Croatia
Joined November 2008
👀Blog with full details & more updates can be found here: https://t.co/YP35k2Mweq
#npm #OSS #SoftwareSupplyChainSecurity #Shaihulud @ap0x
reversinglabs.com
Shai-hulud 2.0 malware has spread to 795 npm packages — with a combined download count of more than 100 million.
RL automated threat detection system is detecting a new wave of Shai-hulud #npm packages. Look out for RL's TH15502 policy violation in npm packages. The campaign affects popular [@]asyncapi packages with millions of downloads. Here is an example -
0
3
5
@ReversingLabs This new worm variant includes wiper functionality. Shai-hulud permanently destroy all data in the user's home directory making it unrecoverable. It overwrites the free space where the deleted files used to be. Ensuring that data recovery software cannot restore the files.
0
0
0
@ReversingLabs Just like with the first wave, automated dependency management tools (like DependaBot) are creating pull requests that are helping the worm spread.
1
0
0
@ReversingLabs Over 25k repositories containing environment secrets, and other private information, have been published on GitHub by the accounts affected by this new Shai-Hulud wave.
1
0
0
RL automated threat detection systems are detecting the new wave of Shai-Hulud npm packages. Look out for the TH15502 policy violation in our Spectra Assure Community. Here is an example of a compromised package: https://t.co/uitFAHk3e5 - More info to follow from @ReversingLabs
secure.software
Supply chain risk analysis for @asyncapi/[email protected]. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
1
1
1
After detecting & mitigating multiple supply chain attacks targeting #OSS the past few weeks, RL co-founder & CSA @ap0x had a gut reaction: "Something has to change, because we can’t keep doing this every week." #npm #GitHub
reversinglabs.com
As the development community chalks up the npm worm as just another bad day, bigger questions remain about the software supply chain ecosystem.
0
1
2
⚠️ RL researchers have found another package compromised on day 3 of the ongoing #npm #phishing campaign. It hides the obfuscated payload in the middle of an already large index.js file.👇
secure.software
Supply chain risk analysis for @magda/[email protected]. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
0
2
7
⚠️🧵 RL researches have detected a supply chain attack in an #npm package with a total download count of over 2 million: https://t.co/emdTgwf0Ig
#OSS #Dev
secure.software
Supply chain risk analysis for [email protected]. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
1
4
7
It's been a busy day for us! ⚠️🧵 RL's automated detection system flagged a new malicious #PyPI package: https://t.co/Jypl3CU9Eb While name would suggest this is a ChatGPT related project, it actually contains a #malware loader.
1
3
2
⚠️🧵 RL researches have detected a supply chain attack in a #VSCode extension that has nearly 6000 installs:
secure.software
Supply chain risk analysis for ETHcode. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
1
6
8
⚠️ 🧵 RL researchers have identified yet another #npm package that uses malicious patching of local software to hijack #cryptocurrency transfers. Get the full story.👇
reversinglabs.com
RL researchers have identified yet another npm package that uses malicious patching of local software to hijack cryptocurrency transfers.
0
4
9
⚠️🧵 For the first time, RL researchers discovered malicious locally-installed #npm packages infecting other legitimate packages. This approach reveals a high level of sophistication on the threat actor’s part:
reversinglabs.com
For the first time, RL researchers discover malicious locally-installed npm packages infecting other legitimate packages.
1
3
5
⚠️🧵 RL researchers have found 2 malicious #VSCode extensions, "ahban.shiba" & "ahban.cychelloworld," that deliver #ransomware in development to it's users.
4
38
129
⚠️🧵 RL researchers detected a new malicious campaign targeting #PyPI users. Several packages are pretending to be "time" related utilities, but are actually used to steal sensitive data like cloud tokens.
1
18
44
Report: Epidemic of Flaws in Commercial and Open Source Code Fuels Attacks @ReversingLabs #OSS #softwaresupplychain #cybersecurity #appsec #report
https://t.co/C1t2riWmhE via @securityledger
0
2
3
⚠️ #ML devs, take note: RL threat researchers have identified nullifAI, a novel attack technique used on ML models hosted on #HuggingFace.
reversinglabs.com
Developers working on machine learning take note: RL threat researchers have identified nullifAI, a novel attack technique used on Hugging Face.
1
4
4
The @ReversingLabs #ThreatResearch team discovered #nullifAI, a novel attack technique used on an #ML model hosted on #HuggingFace. Get the details here:
reversinglabs.com
Developers working on machine learning take note: RL threat researchers have identified nullifAI, a novel attack technique used on Hugging Face.
0
1
5
⚡ Witnessing a landmark year in 2024, RL Spectra Assure achieved a customer growth of more than 150%, & we flagged over 5Bn unique malicious files. #Cybersecurity #Malware #SoftwareSupplyChainSecurity
0
1
4