
Philipp Burckhardt
@burckhap
Followers
2K
Following
5K
Media
52
Statuses
7K
⚡Securing Software Supply Chains at @SocketSecurity (https://t.co/rjmrp0fCL0) 🔭 Scientific computing for the web via @stdlibjs (https://t.co/nJc4oxoUlD)
Pittsburgh, PA
Joined October 2010
GraphMaker for easy graph building: describe in English what nodes and edges you want, and it handles the rest via OpenAI's help. Support for trees, DAGs, styling, saving in multiple formats etc. Work in progress, please send @CRGenovese and me feedback!.
github.com
GraphMaker is a tool for creating, manipulating, and exporting graphs using natural language. - isle-project/graphmaker
1
1
3
On the @stdlibjs blog, we just published my take on @METR_Evals's surprising study: AI tools made experienced developers 19% slower (expectation: 40% faster!)🤯.I dive into the why, where AI coding tools actually help, and how I've shifted from handholding AI to async delegation.
1
0
2
These packages, disguised as "the cheapest Cursor API," install backdoors that steal credentials and modify crucial files. In total, sw-cur, sw-cur1, and aiide-cur have been downloaded 3,200+ times before discovery. Read more on the Socket blog: .
socket.dev
Malicious npm packages posing as developer tools target macOS Cursor IDE users, stealing credentials and modifying files to gain persistent backdoor a...
0
0
0
The attack takes advantage of the open nature of Go's ecosystem, where it is challenging to distinguish authentic packages from malicious ones due to namespace ambiguity. Check out our detailed analysis, IOCs, and protective measures: #CyberSecurity
0
2
2
The threat actor started publishing these packages in 2021, consistently employing comparable strategies while remaining undetected. Full technical analysis here:.
socket.dev
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
0
3
4
Remember: If any code asks for your seed phrase, there's no salvation - it's not a feature, it's a scam. Full research here:
socket.dev
Socket researchers uncovered malicious npm and PyPI packages that steal crypto wallet credentials using Google Analytics and Telegram for exfiltration...
0
0
0