tuckner Profile Banner
tuckner Profile
tuckner

@tuckner

Followers
2K
Following
10K
Media
646
Statuses
4K

Finding bad software extensions at https://t.co/dhLUjMRP1I

Kansas City, MO
Joined May 2008
Don't wanna be here? Send us removal request.
@TheCyberSecHub
The Cyber Security Hub™
4 days
Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities
Tweet card summary image
thehackernews.com
AI-created VS Code malware and fake npm packages reveal how attackers exploit open-source trust.
0
2
2
@tuckner
tuckner
10 hours
Extension marketplaces for browsers, code editors, MCP, and more are all designed for consumers and not businesses. They do not want to remove extensions if they don't have to. The risks an individual accepts are not the same as the risks your company does.
0
2
6
@tuckner
tuckner
12 hours
Definitely not staging something
1
0
2
@AndrewMohawk
AndrewMohawk⁽ⁿᵘˡˡ⁾
12 hours
@PatrickAlphaC Please be aware that *all* the market places are filled with malware, just follow @secureannex to see. Make sure you validate what they are _before_ you install!
0
2
5
@tuckner
tuckner
13 hours
Powerful new Detections are added to Secure Annex. These are already catching subtle exploits like unicode extension names that evade other filters, manipulated download counts, and combinations of suspicious signatures in code.
0
1
3
@tuckner
tuckner
1 day
GitHub and Google testing VS Marketplace security controls?! Glad to see the test attempts have moved on from actually installing a C2 to instead just popping calc. https://t.co/H8RWmR6Ezc
0
0
2
@tuckner
tuckner
2 days
Another edition of "Guess the right solidity". Two of these will compromise your machine the moment you hit install.
30
28
515
@tuckner
tuckner
2 days
Also these domain names are 🤌 https://t.co/2tXzCNKL7g
2
0
13
@tuckner
tuckner
2 days
You can use unicode in VS Code extension names which probably defeats a lot of filters
@tuckner
tuckner
1 month
You can use unicode in Firefox extension names which probably defeats a lot of filters.
1
8
175
@tuckner
tuckner
3 days
This is the VS Code extension that I was looking at
0
0
2
@tuckner
tuckner
3 days
@tuckner
tuckner
3 days
It's Mythic!
1
0
7
@tuckner
tuckner
3 days
It's Mythic!
@tuckner
tuckner
3 days
Never a dull day
0
0
2
@tuckner
tuckner
3 days
GitHub and Google?! Nice
0
0
2
@tuckner
tuckner
3 days
Whats up 𝐁𝐁?
0
0
2
@CSOonline
CSOonline
3 days
Vibe-coded ransomware proof-of-concept ended up on Microsoft’s marketplace https://t.co/mAMDvzVIf2
0
1
1
@tuckner
tuckner
3 days
What are chances a 'fonts.js' file that is actually a MacOS script which has variables like 'removedAsian' and is heavily encoded might just be malicious?
1
1
10
@tuckner
tuckner
3 days
Never a dull day
3
8
93
@tuckner
tuckner
4 days
0
1
2
@tuckner
tuckner
4 days
Ridiculously cool that Tines is able to connect to MCP servers now. Understand entirely what any of the browser or code extensions you use might actually be doing with a simple ask. Orchestrate your extension review process or check if "Hello Kitty - You Glow Girl Cute Live
2
2
4