A bunch of packages published by qix in NPM just got backdoored it looks like. Obfuscated code was added like two hours ago. #threatintel #npm
For example: https://www.npmjs.com/package/is-arrayish?activeTab=code
I think quite a few packages are impacted, potentially some very high volume ones. I gotta hop on a subway to make a plane though so it’s going to be hard for me to keep digging.
A bunch of packages published by qix in NPM just got backdoored it looks like. Obfuscated code was added like two hours ago. #threatintel #npm
Interesting write-up coming out of Lab52 where #APT28 (aka Fancy Bear) appear to be using a backdoor communicating through MAPI and Outlook, ie. using email as a C2-channel with base64 encoded instructions etc.
https://lab52.io/blog/analyzing-notdoor-inside-apt28s-expanding-arsenal/
2/ i wrote a short-ish "note" over on The Blogging Site That Shall Not Be Named in an attempt to explain to the less technologically sophisticated people in the audience what just happened with the #nx / #npm supply chain attack.
* my simplified explanation: https://substack.com/profile/96801203-michel-de-cryptadamus/note/c-149738571
* for the trve heads with opinions on things like linux distros and the Rust programming language, Wiz wrote a much more thorough explanation: https://www.wiz.io/blog/s1ngularity-supply-chain-attack
#crypto #cryptocurrency #nodejs #node #threatintel #northkorea #lazarusgroup#DPRK #hackers #hacking #ethereum #claude #gemini
everyone calm down, the enormous #NPM supply chain attack of the incredibly popular (27,000 #github stars) #nx#AI build tool thingamajig is probably aimed solely at crypto bros. if you don't have any crypto you (hopefully) don't have anything to worry about.
my fact free, completely unsupported by evidence hunch is that we will find this came from #NorthKorea (because if it's a well orchestrated attempt to steal a bunch of crypto it's pretty much always north korea).
https://universeodon.com/@cryptadamist/115102035321832152
#crypto #cryptocurrency #ethereum #npm #nodejs #node #js#javascript#webdev#DPRK#LazarusGroup #cybersecurity #infosec #threatintel #claude #gemini
Seeing an influx of spam from a few big Mastodon servers, perfect timing for FediThreat to ship along with the big Stories release!
It's going to be a busy and fun weekend 🚀
Seeing an influx of spam from a few big Mastodon servers, perfect timing for FediThreat to ship along with the big Stories release!
It's going to be a busy and fun weekend 🚀
everyone calm down, the enormous #NPM supply chain attack of the incredibly popular (27,000 #github stars) #nx#AI build tool thingamajig is probably aimed solely at crypto bros. if you don't have any crypto you (hopefully) don't have anything to worry about.
my fact free, completely unsupported by evidence hunch is that we will find this came from #NorthKorea (because if it's a well orchestrated attempt to steal a bunch of crypto it's pretty much always north korea).
https://universeodon.com/@cryptadamist/115102035321832152
#crypto #cryptocurrency #ethereum #npm #nodejs #node #js#javascript#webdev#DPRK#LazarusGroup #cybersecurity #infosec #threatintel #claude #gemini
2/ i wrote a short-ish "note" over on The Blogging Site That Shall Not Be Named in an attempt to explain to the less technologically sophisticated people in the audience what just happened with the #nx / #npm supply chain attack.
* my simplified explanation: https://substack.com/profile/96801203-michel-de-cryptadamus/note/c-149738571
* for the trve heads with opinions on things like linux distros and the Rust programming language, Wiz wrote a much more thorough explanation: https://www.wiz.io/blog/s1ngularity-supply-chain-attack
#crypto #cryptocurrency #nodejs #node #threatintel #northkorea #lazarusgroup#DPRK #hackers #hacking #ethereum #claude #gemini
everyone calm down, the enormous #NPM supply chain attack of the incredibly popular (27,000 #github stars) #nx#AI build tool thingamajig is probably aimed solely at crypto bros. if you don't have any crypto you (hopefully) don't have anything to worry about.
my fact free, completely unsupported by evidence hunch is that we will find this came from #NorthKorea (because if it's a well orchestrated attempt to steal a bunch of crypto it's pretty much always north korea).
https://universeodon.com/@cryptadamist/115102035321832152
#crypto #cryptocurrency #ethereum #npm #nodejs #node #js#javascript#webdev#DPRK#LazarusGroup #cybersecurity #infosec #threatintel #claude #gemini
Detailed report coming out of CISA regarding Chinese State-Sponsored Actors.
All the names, all the cybers.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a
Detailed report coming out of CISA regarding Chinese State-Sponsored Actors.
All the names, all the cybers.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a
I find this report by Group-IB quite intriguing since it would appear to suggest a collaboration between Chinese and Russian actors.
That itself is interesting and would appear to mimic the geopolitical landscape where Russia and China are quite cozy.
New loot coming out of DTI @DomainTools and it would appear as if our dear friend @neurovagrant has been at it again? 🙂
I'm still mad that firewall vendors have their heads up their AI's asses and won't enable blocking by ASN. So here is the ASN-DROP list from @spamhaus but I pulled the advertised prefixes for them all so you can block the networks in your firewalls. Or at least look into it.
Fuck you, vendors. 🖕
Yet another AitM campaign. This one on Secret Blizzard is written up by Microsoft.
Good thing Macs can't get malware, otherwise this SentinelOne post about ZuRu making a comeback might be worth looking into. IOCs in the post.
For the past few weeks, @DomainTools Investigations worked with OSINT analyst and investigative journalist grantees to help uncover connections between websites involved in the harassment of Ukrainian personnel and their families, and the people and infrastructure involved.
We provide a technical writeup below on the observables and data involved.
#infosec #cybersecurity #threatintel #disinformation
https://www.domaintools.com/resources/blog/rdap-and-bgp-in-investigative-journalism/
For the past few weeks, @DomainTools Investigations worked with OSINT analyst and investigative journalist grantees to help uncover connections between websites involved in the harassment of Ukrainian personnel and their families, and the people and infrastructure involved.
We provide a technical writeup below on the observables and data involved.
#infosec #cybersecurity #threatintel #disinformation
https://www.domaintools.com/resources/blog/rdap-and-bgp-in-investigative-journalism/
"Britain’s drug gangs and Moscow’s hackers were just two nodes in a vast criminal super-network [that] included sanctioned oligarchs, Russian intelligence operatives and an Irish crime family."
(and of course that network also now includes the #Trump administration, because Howard Lutnick is/was Tether's money manager)
* #TheEconomist: https://www.economist.com/1843/2025/07/04/how-tether-became-money-launderers-dream-currency
* no paywall: https://archive.ph/NiCRD
#moneylaundering #crime#corruption #crypto #cryptocurrency #iran #russia #uspol#howardLutnick #economist #economics #finance #uk #ukpol #garantex #threatintel #ransomware #cybersecurity #vladimirputin #oligarchs #putin #ukraine #kinahans #kinahan