6mile @6mile.githax.com · 01/02/2026Heya @steipete.me can you do something about malicious skills in your ClawHub registry? Last night, one user published 200 malicious skills. I am tracking a dozen threat actors all publishing multiple malicious skills into this registry, and I've emailed you about all of them, but got crickets back 011
6mile @6mile.githax.com · 17/12/2025Another day, and another @hacker0x01.bsky.social "researcher" ganking people's AWS keys in a public NPM package (plugin-senna). 🤦♀️ 000
6mile @6mile.githax.com · 12/11/2025I've identified a new worm affecting NPM. I'm calling it "IndonesianFoods" based on its internal dictionary. The intent is to generate assets on the Tea Protocol blockchain. It's dumb, but it's MASSIVE! Check the link 👉 sourcecodered.com/indonesianfo... @npmjs.bsky.social @github.com 001
6mile @6mile.githax.com · 16/10/2025Don't let AI write your payloads for you if you don't know what you're doing. Otherwise, you might end up publishing your API keys, environment variables, and identity to @npmjs.bsky.social 001
6mile @6mile.githax.com · 08/10/2025Want to sniff out private bug bounty programs? If you monitor OSV for new malicious packages, you'll get some great intel. Today's example: @npmjs.bsky.social user Paastha published 6 packages targeting @vercel.com. But wait, they don't have a BB program?! Or do they.... 😮💥 010
6mile @6mile.githax.com · 08/10/2025Tell me that @v0.dev has a bug bounty program without telling me they have a bug bounty program. #dependencyconfusion #maliciouspackage 011
6mile @6mile.githax.com · 09/08/2025See me at 11 am today on the #DEFCON Creator State 4 (room 228). I'm super excited for this, and a big "thank you!" to the #AdversaryVillage team! #hackersummercamp @github.com 010
6mile @6mile.githax.com · 14/07/2025I'm the first presentation for Adversary Village at @defcon.bsky.social. See me talk about open-source malware at 11 am on Saturday, August 9, in room 228 (creator stage 4) 020
6mile @6mile.githax.com · 06/07/2025Heya @virginaustralia.bsky.social I just tried to buy tickets for $6903 as advertised, but turns out it's a bait & switch. Real price: $11,617. VA support blames it on "website latency" but that price still on site. Wonder what Australian ACCC will make of VA advertising fares that don't exist? 121
6mile @6mile.githax.com · 02/04/2025You can't make this shit up! The NIST NVD database has been down all day, so no one can look up CVEs via NVD. @shodanhq.bsky.social reports that one of the two ec2 instances serving up the NVD website reports a "402 Payment Required". Did DOGE dipshits break our national vulnerability database?! 110
6mile @6mile.githax.com · 14/01/2025My blog post is top spot on Hackernews! Woot! @hackernewsbot.bsky.social #softwaresupplychain 250
6mile @6mile.githax.com · 14/01/2025Quickest turnaround in MONTHS from NPM as they've taken down the marked-cs and marked-ps malicious packages in less than a day! Woot! @npmjs.bsky.social #softwaresupplychain #npm 010
6mile @6mile.githax.com · 08/01/2025Did a security researcher at Snyk really just publish malicious packages to NPM targeting Cursor.com? 2398
6mile @6mile.githax.com · 06/01/2025If you are using crypto/web3 libraries be aware that many npm packages that claim to be a part of @solana.com or @walletconnect.bsky.social ecosystems are malicious. For example, the solanacore, walletcore-gen and solana-login @npmjs.bsky.social packages drop infostealers on hosts and exfil data. 021
6mile @6mile.githax.com · 19/12/2024Attackers compromised the popular rspack/core & rspack/cli NPM packages owned by @bytedance.bsky.social. The attackers published version 1.1.7 for both packages, which deployed the xmrig crypto miner & sent all tokens to the IP 80[.]78.28.72. These packages are downloaded thousands of times a week 041
6mile @6mile.githax.com · 18/12/2024BREAKING NEWS! Six packages were just published to the NPM registry, delivering a new MacOS malware. Do not install these packages! #softwaresupplychain #malware @npmjs.bsky.social 010
6mile @6mile.githax.com · 13/12/2024A @npmjs.bsky.social package named discord-json-scaller was published on 12/7 & removed on 12/12. It contained an elegant Discord injection attack written by the same author of hackirby/skuld. It intercepts login, registration & 2FA requests, email & password changes, credit card payments & more. 000
6mile @6mile.githax.com · 11/12/2024Woot! My first three CFP/CFT submissions for 2025 have come back accepted! Stoked! 030
6mile @6mile.githax.com · 07/12/2024#Ultralytics has been compromised again tonight. This is the second time in two days that bad guys have leveraged a nifty shell injection bug in Actions. Maybe it's time to stop using this library. I mean, fool me once, shame on you. Fool me twice, shame on me, right? 010
6mile @6mile.githax.com · 04/12/2024I identified a software supply chain attack today affecting the @solana.com web3.js NPM package. One of the project collaborators' creds (to NPM?) were compromised which allowed the threat actors to deploy two malicious versions to NPM: 1.95.6 and 1.95.7. The bad guys added a function that .... 122