Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to add "Enterprise-grade" obfuscation We discovere…
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to add "Enterprise-grade" obfuscation We discovere…
Over the past couple of months, the attacker has been distributing trojans from several npm accounts: alex05255, mdrafiqulislamrabby, b.w1001, abdev8773, and mo…
Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher Nicholas Curran He published packages wit…
Hello! The Supply Chain Security group is here 🩷 We scan open source in real time for malicious code. We are also responsible at ESCalator for publications abou…
Attacker publishes .bash_history watch without registration and SMS 😱 The Supply Chain Security team sent a report to the npm registry administration about an a…
A logging library and an infostealer to boot? No thanks 👋 A lot has happened recently. For example, someone decided to play patron of the arts and published 30…
Unusual obfuscation is always beautiful... 🥰 ... it's just a shame that you have to see it in trojanized open-source packages, and not only at Capture The Flag…
pip install teligram 🧐 (better not run it) On February 8, the teligram library was published. Its description reads: Telegram-based friendly library. Alas, as u…
The city celebrates, the mafia wakes up 🥰 Between January 1 and 11, approximately 180 malicious packages were removed from the NPM ecosystem, and 16 from PyPI…
Attackers compromised dozens of NPM packages with ~2 billion downloads 🐾 What happened As part of a phishing campaign, maintainer Josh "Qix" Junon was…
Node JS. Malicious activity at the installation stage As part of researching the actions of attackers in npm (Node Package Manager, the main repository of JS co…
Drama around PyPI: 🪰⮕🐘? Last week, CNews published a news item: "Russians driven out of the Python community. Only the chosen ones for now, but the selection cr…