Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kurmiashish
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Pythagora-Io/GPT-Pilot Compromised Credential Stealer Blocked by Python Linter
(github.com)
2 points
by
kurmiashish
3mo ago
|
1 comments
2.
▲
by
kurmiashish
3mo ago
An attacker hijacked a co-founder's GitHub account for gpt-pilot, a 33K-star AI coding tool, and force-pushed a credential-stealing Shai-Hulud payload to the main branch. The ruff Python linter caught formatting and lint violations in
3.
▲
Malicious npm packages detected across Red Hat Cloud Services
(github.com)
775 points
by
kurmiashish
4mo ago
|
454 comments
4.
▲
by
kurmiashish
4mo ago
Three malicious versions of Microsoft's official durabletask Python SDK were published to PyPI on May 19, 2026. The compromised package silently downloads and executes a 28 KB payload that steals credentials from AWS, Azure, GCP, Kuber
5.
▲
Malicious IoliteLabs VSCode Extensions Target Solidity Developers with Backdoor
(stepsecurity.io)
2 points
by
kurmiashish
6mo ago
|
0 comments
6.
▲
Ctrl/tinycolor and 40 NPM Packages Compromised
(stepsecurity.io)
3 points
by
kurmiashish
1y ago
|
1 comments
7.
▲
by
kurmiashish
1y ago
The popular @ctrl/tinycolor package, which receives over 2 million weekly downloads, has been compromised along with more than 40 other packages across multiple maintainers. This attack demonstrates a concerning evolution in supply cha
8.
▲
AI coding agents in CI/CD pipelines create new attack vectors
(stepsecurity.io)
2 points
by
kurmiashish
1y ago
|
1 comments
9.
▲
by
kurmiashish
1y ago
This article explores how AI coding agents (GitHub Copilot, Claude Code, etc.) operating in CI/CD environments introduce novel security risks that traditional EDR solutions can't detect. The key insight: these agents have elevated
10.
▲
by
kurmiashish
2y ago
@rahulr0609 https://github.com/step-security/changed-files will forever remain free, and the community can use it without requiring a StepSecurity subscription.
11.
▲
by
kurmiashish
2y ago
Due to the ongoing security incident involving the tj-actions/changed-files Action, we at StepSecurity have provided a secure, drop-in replacement: step-security/changed-files. We strongly advise replacing all instances of tj-acti
12.
▲
by
kurmiashish
2y ago
Thank you, cyrnel, for the feedback! We are trying our best to help serve the community. Now, we have separate recovery steps for general users and our enterprise customers.
13.
▲
by
kurmiashish
2y ago
Disclaimer: I am a co-founder of StepSecurity. StepSecurity Harden-Runner detected this security incident by continuously monitoring outbound network calls from GitHub Actions workflows and generating a baseline of expected behaviors. When
14.
▲
Show HN: GitHub Actions Goat – Deliberately Vulnerable CI/CD Environment
(github.com)
7 points
by
kurmiashish
3y ago
|
0 comments
15.
▲
S3Insights: Derive insights about your S3 environment at scale
(medium.com)
4 points
by
kurmiashish
6y ago
|
0 comments