Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tomabai
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
29 ms
·
1.
▲
by
tomabai
1y ago
TLDR You can easily make your NPM package look popular with a minimal script with no barriers at all. Read the short story here - https://www.linkedin.com/posts/tom-abai-a4862915a_osssupplyc...
2.
▲
by
tomabai
2y ago
I get your point and agree with that, but i think that the technique used here was interesting
3.
▲
by
tomabai
2y ago
The package was published on npm, the original extension, has a private component on npm with a similar name to that package, and that the squat the attacker tried to take advantage of
4.
▲
by
tomabai
2y ago
Nice, I also did in our website https://www.mend.io/blog/fake-vs-code-extension-on-npm-sprea...
5.
▲
Fake VS Code Extension on NPM Spreads Multi-Stage Malware
(mend.io)
186 points
by
tomabai
2y ago
|
98 comments
6.
▲
by
tomabai
2y ago
We discover a fake vscode extension that serves a multi-stage malware on npm, Inc. The package uses javascript obfuscation for downloading the first stage of the malware, than it uses a heavily obfuscated batch file to conntinue into the se
7.
▲
by
tomabai
2y ago
Hi guys, I'd like to introduce my new learning platform - LLM Security Labs. This hands-on platform focused on the owasp top 10 for llm risks, where each risk has it own's lab in order to understand each risk with practical challe
8.
▲
A new platform for learning LLM's risks
(llm-sec.dev)
1 points
by
tomabai
2y ago
|
1 comments
9.
▲
Supply Chain Threat Hunting
(mend.io)
1 points
by
tomabai
2y ago
|
0 comments
10.
▲
Typosquatting attack on 'CORS' NPM package and ATO attempt on “just eat” company
(mend.io)
1 points
by
tomabai
4y ago
|
0 comments