Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
louislang
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
louislang
2y ago
DARPA is doing something similar to this with their TRACTOR work. https://www.darpa.mil/program/translating-all-c-to-rust
2.
▲
by
louislang
2y ago
(Full disclosure: I'm one of the co-founders @ Phylum) We could do a full write-up on npm's quirks and how one could take advantage of them to hide intent. Consider the following from the post's package.json: "axio
3.
▲
70% of new NPM packages in last 6 months were spam
(blog.phylum.io)
225 points
by
louislang
2y ago
|
111 comments
4.
▲
Malicious Python Code Gains Execution
(blog.phylum.io)
6 points
by
louislang
2y ago
|
0 comments
5.
▲
The Chinese Room Argument
(plato.stanford.edu)
3 points
by
louislang
2y ago
|
0 comments
6.
▲
Spam: Unintended Consequences of Open Source Sustainability Platforms
(blog.phylum.io)
3 points
by
louislang
2y ago
|
0 comments
7.
▲
by
louislang
2y ago
this is still true of node/npm. It's also true of Cargo (Rust), Nuget (C#), and a handful of others. I'd say it's probably the _norm_ for most ecosystems to allow some form of pre/post-install execution.
8.
▲
by
louislang
2y ago
I'm one of the co-founders @ Phylum. We've been tracking this campaign [1] (along with several other unrelated ones). The collective group of security researchers (Shoutout to https://vipyrsec.com/ ) in our Discord
9.
▲
by
louislang
2y ago
Yeah, the broad campaign makes it extremely noticeable. There are active campaigns right now that don't take this approach. Singular packages with novel malicious payloads. > As a person who regularly runs pip install on my main des
10.
▲
by
louislang
2y ago
No, this is not unique to Python or PyPI. I'm one of the co-founders @ Phylum. We've tracked campaigns across Crates.io, Nuget, npm, PyPi, etc. see: https://blog.phylum.io/tag/research/
11.
▲
PyPI Suspends New User and Project Creation in Wake of Malware Campaign
(blog.phylum.io)
16 points
by
louislang
2y ago
|
7 comments
12.
▲
by
louislang
3y ago
Seems like gaming tax makes up for the loss of personal income tax.
13.
▲
by
louislang
3y ago
Yeah, 1.1.[5,6,7] were involved in the attack.
14.
▲
by
louislang
3y ago
Co-founder @ Phylum here ( https://phylum.io ). We've been actively scanning dependencies across most open source package registries (e.g., npm, PyPI, Crates.io, etc.) for a few years now. Quite successfully, I might add, wit
15.
▲
by
louislang
3y ago
People approach things through a lens of familiarity. Programmers are likely relating it to their experience.
16.
▲
Malicious Nuget Packages Found Delivering SeroXen Malware
(blog.phylum.io)
2 points
by
louislang
3y ago
|
0 comments
17.
▲
by
louislang
3y ago
One of the sources referenced in the paper is about the work the company I co-founded is doing ( https://phylum.io ). We've been working closely with PyPI to not only report issues related to malware, but are also helping pro
18.
▲
by
louislang
3y ago
What makes you say that? There doesn't seem to be a ton of info on that page about _what_ it is. Certainly not enough to call it an after though.
19.
▲
by
louislang
3y ago
The fact that I'm in Houston and have grown accustomed to the threat of yearly hurricanes is personally alarming.
20.
▲
by
louislang
3y ago
Happy to see this on HN! I'm one of the co-founders @ Phylum. We actively monitor and report on malware and software supply chain attacks across multiple ecosystems. Most notably, we were the first to identify and report on attacks car
21.
▲
by
louislang
3y ago
Sorry, I just saw this! We actively monitor each open source repository and as packages are published, we pull them down and analyze each line of code and any associated metadata. We also pull as much information as we can get from VCS plat
22.
▲
by
louislang
3y ago
It's some stupid blog setting. I just disabled it. Thanks for the heads up!
23.
▲
by
louislang
3y ago
Response time was one of the best we've experienced at Phylum. It's obvious you guys are putting in a ton of work over there. Please let me know if there's anything we can help out with!
24.
▲
by
louislang
3y ago
Yes, we (Phylum) work closely with Github and reported this account to them.
25.
▲
by
louislang
3y ago
We're actively working on this with our sandbox ( https://github.com/phylum-dev/birdcage ). We've wrapped the likes of pip, yarn, and npm already and are making moves to similarly provide support for cargo. Cur
26.
▲
by
louislang
3y ago
Happy to see this on HN! I'm one of the co-founders @ Phylum. We actively monitor and report on malware and software supply chain attacks across multiple ecosystems. Most notably, we were the first to identify and report on attacks car
27.
▲
‘Flying aliens’ harassing village in Peru are illegal miners with jetpacks: cops
(vice.com)
45 points
by
louislang
3y ago
|
23 comments
28.
▲
Speeding up NMAP service scanning 16x
(joshua.hu)
2 points
by
louislang
3y ago
|
0 comments
29.
▲
by
louislang
3y ago
the problem with GPT is that you're not guaranteed to get something that's _accurate_. I'd definitely prefer some input from an expert over GPT.
30.
▲
The Clean Energy Future Is Roiling Both Friends and Foes
(nytimes.com)
2 points
by
louislang
3y ago
|
0 comments
More ›