Sign in

6mile

@6mile.githax.com
250 followers 530 following 75 posts

Software Supply Chain Red Team. SourceCodeRED & SecureStack founder, dad, startup OG, snowboarder and hacker. Workin on GitHax tool in my spare time. github.com/6mile @eastsidemccarty from the bird site.

PostsRepliesMedia
6mile @6mile.githax.com · 12/05/2026
Famous oxymorons
010
6mile @6mile.githax.com · 01/02/2026
Heya @steipete.me can you do something about malicious skills in your ClawHub registry? Last night, one user published 200 malicious skills. I am tracking a dozen threat actors all publishing multiple malicious skills into this registry, and I've emailed you about all of them, but got crickets back
011
6mile @6mile.githax.com · 06/01/2026
Touche.
010
6mile @6mile.githax.com · 17/12/2025
Another day, and another @hacker0x01.bsky.social "researcher" ganking people's AWS keys in a public NPM package (plugin-senna). 🤦‍♀️
000
6mile @6mile.githax.com · 15/12/2025
Bug bounty peeps, yo
010
6mile @6mile.githax.com · 12/11/2025
I've identified a new worm affecting NPM. I'm calling it "IndonesianFoods" based on its internal dictionary. The intent is to generate assets on the Tea Protocol blockchain. It's dumb, but it's MASSIVE! Check the link 👉 sourcecodered.com/indonesianfo... @npmjs.bsky.social @github.com
001
6mile @6mile.githax.com · 23/10/2025
I like the one-two combo you got going there picklerick
110
6mile @6mile.githax.com · 16/10/2025
Don't let AI write your payloads for you if you don't know what you're doing. Otherwise, you might end up publishing your API keys, environment variables, and identity to @npmjs.bsky.social
001
6mile @6mile.githax.com · 08/10/2025
Want to sniff out private bug bounty programs? If you monitor OSV for new malicious packages, you'll get some great intel. Today's example: @npmjs.bsky.social user Paastha published 6 packages targeting @vercel.com. But wait, they don't have a BB program?! Or do they.... 😮💥
010
6mile @6mile.githax.com · 08/10/2025
Tell me that @v0.dev has a bug bounty program without telling me they have a bug bounty program. #dependencyconfusion #maliciouspackage
011
6mile @6mile.githax.com · 07/10/2025
Heya homie, that ain't gonna work.
000
6mile @6mile.githax.com · 17/09/2025
021
6mile @6mile.githax.com · 28/08/2025
000
6mile @6mile.githax.com · 09/08/2025
See me at 11 am today on the #DEFCON Creator State 4 (room 228). I'm super excited for this, and a big "thank you!" to the #AdversaryVillage team! #hackersummercamp @github.com
010
6mile @6mile.githax.com · 17/07/2025
The apocalypse is upon us!
000
6mile @6mile.githax.com · 14/07/2025
I'm the first presentation for Adversary Village at @defcon.bsky.social. See me talk about open-source malware at 11 am on Saturday, August 9, in room 228 (creator stage 4)
020
6mile @6mile.githax.com · 06/07/2025
Heya @virginaustralia.bsky.social I just tried to buy tickets for $6903 as advertised, but turns out it's a bait & switch. Real price: $11,617. VA support blames it on "website latency" but that price still on site. Wonder what Australian ACCC will make of VA advertising fares that don't exist?
121
6mile @6mile.githax.com · 09/05/2025
110
6mile @6mile.githax.com · 02/04/2025
You can't make this shit up! The NIST NVD database has been down all day, so no one can look up CVEs via NVD. @shodanhq.bsky.social reports that one of the two ec2 instances serving up the NVD website reports a "402 Payment Required". Did DOGE dipshits break our national vulnerability database?!
110
6mile @6mile.githax.com · 14/01/2025
My blog post is top spot on Hackernews! Woot! @hackernewsbot.bsky.social #softwaresupplychain
250
6mile @6mile.githax.com · 14/01/2025
Quickest turnaround in MONTHS from NPM as they've taken down the marked-cs and marked-ps malicious packages in less than a day! Woot! @npmjs.bsky.social #softwaresupplychain #npm
010
6mile @6mile.githax.com · 10/01/2025
Spotted
020
6mile @6mile.githax.com · 08/01/2025
Did a security researcher at Snyk really just publish malicious packages to NPM targeting Cursor.com?
2398
6mile @6mile.githax.com · 06/01/2025
If you are using crypto/web3 libraries be aware that many npm packages that claim to be a part of @solana.com or @walletconnect.bsky.social ecosystems are malicious. For example, the solanacore, walletcore-gen and solana-login @npmjs.bsky.social packages drop infostealers on hosts and exfil data.
021
6mile @6mile.githax.com · 21/12/2024
Happy holidays from #badsanta!
010
6mile @6mile.githax.com · 19/12/2024
Attackers compromised the popular rspack/core & rspack/cli NPM packages owned by @bytedance.bsky.social. The attackers published version 1.1.7 for both packages, which deployed the xmrig crypto miner & sent all tokens to the IP 80[.]78.28.72. These packages are downloaded thousands of times a week
041
6mile @6mile.githax.com · 18/12/2024
BREAKING NEWS! Six packages were just published to the NPM registry, delivering a new MacOS malware. Do not install these packages! #softwaresupplychain #malware @npmjs.bsky.social
010
6mile @6mile.githax.com · 16/12/2024
Shodan is down!
000
6mile @6mile.githax.com · 13/12/2024
A @npmjs.bsky.social package named discord-json-scaller was published on 12/7 & removed on 12/12. It contained an elegant Discord injection attack written by the same author of hackirby/skuld. It intercepts login, registration & 2FA requests, email & password changes, credit card payments & more.
000
6mile @6mile.githax.com · 11/12/2024
Woot! My first three CFP/CFT submissions for 2025 have come back accepted! Stoked!
030
6mile @6mile.githax.com · 11/12/2024
Is there a special @hacker0x01.bsky.social badge for this?
110
6mile @6mile.githax.com · 07/12/2024
#Ultralytics has been compromised again tonight. This is the second time in two days that bad guys have leveraged a nifty shell injection bug in Actions. Maybe it's time to stop using this library. I mean, fool me once, shame on you. Fool me twice, shame on me, right?
010
6mile @6mile.githax.com · 04/12/2024
I identified a software supply chain attack today affecting the @solana.com web3.js NPM package. One of the project collaborators' creds (to NPM?) were compromised which allowed the threat actors to deploy two malicious versions to NPM: 1.95.6 and 1.95.7. The bad guys added a function that ....
122