Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. No new npm packages compromised?

No new npm packages compromised?

Scheduled Pinned Locked Moved Uncategorized
26 Posts 14 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchange
    wrote last edited by
    #1

    No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

    starchturrets@mastodon.socialS mccovican@infosec.exchangeM rikusilvola@infosec.exchangeR nuclearoatmeal@beige.partyN huronbikes@cyberplace.socialH 8 Replies Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

      starchturrets@mastodon.socialS This user is from outside of this forum
      starchturrets@mastodon.socialS This user is from outside of this forum
      starchturrets@mastodon.social
      wrote last edited by
      #2

      @cR0w https://github.com/v12-security/pocs/tree/main/qemu

      ciaranmak@mastodon.ieC 1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
      • starchturrets@mastodon.socialS starchturrets@mastodon.social

        @cR0w https://github.com/v12-security/pocs/tree/main/qemu

        ciaranmak@mastodon.ieC This user is from outside of this forum
        ciaranmak@mastodon.ieC This user is from outside of this forum
        ciaranmak@mastodon.ie
        wrote last edited by
        #3

        @starchturrets @cR0w noice, mom and dads malware sandbox got REKT

        starchturrets@mastodon.socialS 1 Reply Last reply
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

          mccovican@infosec.exchangeM This user is from outside of this forum
          mccovican@infosec.exchangeM This user is from outside of this forum
          mccovican@infosec.exchange
          wrote last edited by
          #4

          @cR0w Shenanigans ahoy! https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/

          cr0w@infosec.exchangeC 1 Reply Last reply
          0
          • mccovican@infosec.exchangeM mccovican@infosec.exchange

            @cR0w Shenanigans ahoy! https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote last edited by
            #5

            @McCovican I think that one was published yesterday, which is like three years ago in this week time.

            mccovican@infosec.exchangeM 1 Reply Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              @McCovican I think that one was published yesterday, which is like three years ago in this week time.

              mccovican@infosec.exchangeM This user is from outside of this forum
              mccovican@infosec.exchangeM This user is from outside of this forum
              mccovican@infosec.exchange
              wrote last edited by
              #6

              @cR0w BleepingComputer are getting slow in their old age (likewise).

              1 Reply Last reply
              0
              • ciaranmak@mastodon.ieC ciaranmak@mastodon.ie

                @starchturrets @cR0w noice, mom and dads malware sandbox got REKT

                starchturrets@mastodon.socialS This user is from outside of this forum
                starchturrets@mastodon.socialS This user is from outside of this forum
                starchturrets@mastodon.social
                wrote last edited by
                #7

                @ciaranmak @cR0w I'm not so sure how bad this is in comparison to the embargoed KVM one at https://xchglabs.com/blog/

                ciaranmak@mastodon.ieC 1 Reply Last reply
                0
                • starchturrets@mastodon.socialS starchturrets@mastodon.social

                  @ciaranmak @cR0w I'm not so sure how bad this is in comparison to the embargoed KVM one at https://xchglabs.com/blog/

                  ciaranmak@mastodon.ieC This user is from outside of this forum
                  ciaranmak@mastodon.ieC This user is from outside of this forum
                  ciaranmak@mastodon.ie
                  wrote last edited by
                  #8

                  @starchturrets @cR0w I will report back because tbh if I don't end up out in the pub this evening I'm probably gonna test this one out

                  viss@mastodon.socialV 1 Reply Last reply
                  0
                  • ciaranmak@mastodon.ieC ciaranmak@mastodon.ie

                    @starchturrets @cR0w I will report back because tbh if I don't end up out in the pub this evening I'm probably gonna test this one out

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote last edited by
                    #9

                    @ciaranmak @starchturrets @cR0w oh god yes. docker 0day. shoot that shit right into my veins

                    starchturrets@mastodon.socialS 1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      @ciaranmak @starchturrets @cR0w oh god yes. docker 0day. shoot that shit right into my veins

                      starchturrets@mastodon.socialS This user is from outside of this forum
                      starchturrets@mastodon.socialS This user is from outside of this forum
                      starchturrets@mastodon.social
                      wrote last edited by
                      #10

                      @Viss @ciaranmak @cR0w well runc isn't really a very strong boundary compared to gvisor or kata containers, so I'm not too worried there

                      1 Reply Last reply
                      0
                      • cr0w@infosec.exchangeC cr0w@infosec.exchange

                        No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                        rikusilvola@infosec.exchangeR This user is from outside of this forum
                        rikusilvola@infosec.exchangeR This user is from outside of this forum
                        rikusilvola@infosec.exchange
                        wrote last edited by
                        #11

                        @cR0w here you go https://www.openwall.com/lists/oss-security/2026/05/15/2

                        1 Reply Last reply
                        1
                        0
                        • cr0w@infosec.exchangeC cr0w@infosec.exchange

                          No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                          nuclearoatmeal@beige.partyN This user is from outside of this forum
                          nuclearoatmeal@beige.partyN This user is from outside of this forum
                          nuclearoatmeal@beige.party
                          wrote last edited by
                          #12

                          @cR0w

                          Day ain't over yet.

                          badsamurai@infosec.exchangeB shellsharks@shellsharks.socialS 2 Replies Last reply
                          0
                          • cr0w@infosec.exchangeC cr0w@infosec.exchange

                            No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                            huronbikes@cyberplace.socialH This user is from outside of this forum
                            huronbikes@cyberplace.socialH This user is from outside of this forum
                            huronbikes@cyberplace.social
                            wrote last edited by
                            #13

                            @cR0w maybe all the fire is hiding some fire we don't know about

                            cr0w@infosec.exchangeC 1 Reply Last reply
                            1
                            0
                            • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

                              @cR0w maybe all the fire is hiding some fire we don't know about

                              cr0w@infosec.exchangeC This user is from outside of this forum
                              cr0w@infosec.exchangeC This user is from outside of this forum
                              cr0w@infosec.exchange
                              wrote last edited by
                              #14

                              @huronbikes You mean fire can grow?!

                              huronbikes@cyberplace.socialH 1 Reply Last reply
                              1
                              0
                              • nuclearoatmeal@beige.partyN nuclearoatmeal@beige.party

                                @cR0w

                                Day ain't over yet.

                                badsamurai@infosec.exchangeB This user is from outside of this forum
                                badsamurai@infosec.exchangeB This user is from outside of this forum
                                badsamurai@infosec.exchange
                                wrote last edited by
                                #15

                                @NuclearOatmeal @cR0w

                                Link Preview Image
                                da_667@infosec.exchangeD 1 Reply Last reply
                                0
                                • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                  No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                                  nyanbinary@infosec.exchangeN This user is from outside of this forum
                                  nyanbinary@infosec.exchangeN This user is from outside of this forum
                                  nyanbinary@infosec.exchange
                                  wrote last edited by
                                  #16

                                  @cR0w darf asked nicely

                                  cr0w@infosec.exchangeC 1 Reply Last reply
                                  0
                                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                    No new npm packages compromised? No new Linux kernel 0days? Is everyone waiting for EOD or is Friday no longer the day to publish shenanigans?

                                    J This user is from outside of this forum
                                    J This user is from outside of this forum
                                    jackryder@infosec.exchange
                                    wrote last edited by
                                    #17

                                    @cR0w Gearing up for Monday morning...

                                    Link Preview Image
                                    1 Reply Last reply
                                    0
                                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                      @huronbikes You mean fire can grow?!

                                      huronbikes@cyberplace.socialH This user is from outside of this forum
                                      huronbikes@cyberplace.socialH This user is from outside of this forum
                                      huronbikes@cyberplace.social
                                      wrote last edited by
                                      #18

                                      @cR0w I heard a rumor that it can but it's hard to confirm what with being on fire and all.

                                      1 Reply Last reply
                                      0
                                      • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

                                        @cR0w darf asked nicely

                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchange
                                        wrote last edited by
                                        #19

                                        @nyanbinary That doesn't sound like @darfplatypus ...

                                        darfplatypus@infosec.exchangeD 1 Reply Last reply
                                        0
                                        • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                          @nyanbinary That doesn't sound like @darfplatypus ...

                                          darfplatypus@infosec.exchangeD This user is from outside of this forum
                                          darfplatypus@infosec.exchangeD This user is from outside of this forum
                                          darfplatypus@infosec.exchange
                                          wrote last edited by
                                          #20

                                          @cR0w @nyanbinary 🤐🤐🤐 pending analysis. Sorry y'all.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups