Malware in open source!
Mmaallwwaarree iinn ooppeennssoouurrccee! A notable campaign by a single researcher is unfolding online. The following packages belong to him: User lastbright…
Mmaallwwaarree iinn ooppeennssoouurrccee! A notable campaign by a single researcher is unfolding online. The following packages belong to him: User lastbright…
Attacker published malicious packages deepseeek and deepseekai on the Python Package Index 🐳 The Supply Chain Security team of the Threat Intelligence departmen…
Tools for Working with Python 😦 Attackers are not shy about using Python for their purposes. LazyStealer, packaged with PyInstaller, the Python backdoor in Shad…
First steps on the hacking path 🐱 Open source is an interesting environment for observing how projects evolve. It's fascinating to study the implementation of t…
Through the blockchain to the data ⭐️ Researchers from Socket and Checkmarx have reported on an interesting malicious campaign in NPM. The attackers mimicked pl…
Catching bug hunters again 💀 In one of our previous posts we wrote about traces of bug bounty activity targeting "Yandex". History repeated itself, but this tim…
Open source passions: part two Infostealers 🧋 No one is surprised by them anymore, since this is a popular class of malware, often mentioned in the news. Most t…
Open Source Drama: Mafia, Stealers, and Bug Hunting of Yandex Projects 🐱 Over the past two weeks, a lot of interesting things have happened in the Python Packag…
🤨 Adding bookmarks to open-source repositories? Young man, come with us. As part of threat intelligence, in addition to researching "traditional" malware, we al…