ap0x Profile Banner
Tomislav Pericin Profile
Tomislav Pericin

@ap0x

Followers
2K
Following
4K
Media
21
Statuses
1K

CSA at ReversingLabs LLC. Designs file analysis platforms, engines and reverse engineering tools for fun. Something about unpacking and PE file format.

Republic of Croatia
Joined November 2008
Don't wanna be here? Send us removal request.
@ReversingLabs
ReversingLabs
2 months
👀Blog with full details & more updates can be found here: https://t.co/YP35k2Mweq #npm #OSS #SoftwareSupplyChainSecurity #Shaihulud @ap0x
Tweet card summary image
reversinglabs.com
Shai-hulud 2.0 malware has spread to 795 npm packages — with a combined download count of more than 100 million.
@ReversingLabs
ReversingLabs
2 months
RL automated threat detection system is detecting a new wave of Shai-hulud #npm packages. Look out for RL's TH15502 policy violation in npm packages. The campaign affects popular [@]asyncapi packages with millions of downloads. Here is an example -
0
3
5
@ap0x
Tomislav Pericin
2 months
@ReversingLabs This new worm variant includes wiper functionality. Shai-hulud permanently destroy all data in the user's home directory making it unrecoverable. It overwrites the free space where the deleted files used to be. Ensuring that data recovery software cannot restore the files.
0
0
0
@ap0x
Tomislav Pericin
2 months
@ReversingLabs Just like with the first wave, automated dependency management tools (like DependaBot) are creating pull requests that are helping the worm spread.
1
0
0
@ap0x
Tomislav Pericin
2 months
@ReversingLabs Over 25k repositories containing environment secrets, and other private information, have been published on GitHub by the accounts affected by this new Shai-Hulud wave.
1
0
0
@ap0x
Tomislav Pericin
2 months
RL automated threat detection systems are detecting the new wave of Shai-Hulud npm packages. Look out for the TH15502 policy violation in our Spectra Assure Community. Here is an example of a compromised package: https://t.co/uitFAHk3e5 - More info to follow from @ReversingLabs
secure.software
Supply chain risk analysis for @asyncapi/[email protected]. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
1
1
1
@ReversingLabs
ReversingLabs
4 months
After detecting & mitigating multiple supply chain attacks targeting #OSS the past few weeks, RL co-founder & CSA @ap0x had a gut reaction: "Something has to change, because we can’t keep doing this every week." #npm #GitHub
Tweet card summary image
reversinglabs.com
As the development community chalks up the npm worm as just another bad day, bigger questions remain about the software supply chain ecosystem. 
0
1
2
@ReversingLabs
ReversingLabs
5 months
⚠️ RL researchers have found another package compromised on day 3 of the ongoing #npm #phishing campaign. It hides the obfuscated payload in the middle of an already large index.js file.👇
Tweet card summary image
secure.software
Supply chain risk analysis for @magda/[email protected]. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
0
2
7
@chesscom
Chess.com
7 months
An important update.
2K
14K
312K
@ReversingLabs
ReversingLabs
7 months
It's been a busy day for us! ⚠️🧵 RL's automated detection system flagged a new malicious #PyPI package: https://t.co/Jypl3CU9Eb While name would suggest this is a ChatGPT related project, it actually contains a #malware loader.
1
3
2
@ReversingLabs
ReversingLabs
7 months
⚠️🧵 RL researches have detected a supply chain attack in a #VSCode extension that has nearly 6000 installs:
Tweet card summary image
secure.software
Supply chain risk analysis for ETHcode. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
1
6
8
@ReversingLabs
ReversingLabs
10 months
⚠️ 🧵 RL researchers have identified yet another #npm package that uses malicious patching of local software to hijack #cryptocurrency transfers. Get the full story.👇
Tweet card summary image
reversinglabs.com
RL researchers have identified yet another npm package that uses malicious patching of local software to hijack cryptocurrency transfers.
0
4
9
@ReversingLabs
ReversingLabs
10 months
⚠️🧵 For the first time, RL researchers discovered malicious locally-installed #npm packages infecting other legitimate packages. This approach reveals a high level of sophistication on the threat actor’s part:
Tweet card summary image
reversinglabs.com
For the first time, RL researchers discover malicious locally-installed npm packages infecting other legitimate packages.
1
3
5
@ReversingLabs
ReversingLabs
11 months
⚠️🧵 RL researchers have found 2 malicious #VSCode extensions, "ahban.shiba" & "ahban.cychelloworld," that deliver #ransomware in development to it's users.
4
38
129
@ReversingLabs
ReversingLabs
11 months
⚠️🧵 RL researchers detected a new malicious campaign targeting #PyPI users. Several packages are pretending to be "time" related utilities, but are actually used to steal sensitive data like cloud tokens.
1
18
44
@securityledger
securityledger
11 months
Report: Epidemic of Flaws in Commercial and Open Source Code Fuels Attacks @ReversingLabs #OSS #softwaresupplychain #cybersecurity #appsec #report https://t.co/C1t2riWmhE via @securityledger
0
2
3
@ReversingLabs
ReversingLabs
1 year
⚠️ #ML devs, take note: RL threat researchers have identified nullifAI, a novel attack technique used on ML models hosted on #HuggingFace.
Tweet card summary image
reversinglabs.com
Developers working on machine learning take note: RL threat researchers have identified nullifAI, a novel attack technique used on Hugging Face.
1
4
4
@ReversingLabs
ReversingLabs
1 year
⚡ Witnessing a landmark year in 2024, RL Spectra Assure achieved a customer growth of more than 150%, & we flagged over 5Bn unique malicious files. #Cybersecurity #Malware #SoftwareSupplyChainSecurity
0
1
4