Sign in

6mile

@6mile.githax.com
249 followers 530 following 75 posts

Software Supply Chain Red Team. SourceCodeRED & SecureStack founder, dad, startup OG, snowboarder and hacker. Workin on GitHax tool in my spare time. github.com/6mile @eastsidemccarty from the bird site.

PostsRepliesMedia
6mile @6mile.githax.com · 02/07/2026
We're going live in ten minutes with the @opensourcemalware.bsky.social show! www.linkedin.com/event/manage...
linkedin.com
LinkedIn Login, Sign in | LinkedIn
Login to LinkedIn to keep in touch with people you know, share ideas, and build your career.
000
6mile @6mile.githax.com · 12/05/2026
Famous oxymorons
010
6mile @6mile.githax.com · 12/05/2026
yessss!
000
6mile @6mile.githax.com · 31/03/2026
Tickets to Gold Coast BSides go on sale tomorrow! events.humanitix.com/bsides-goldi...
events.humanitix.com
BSides Goldie 2026
BSides Gold Coast returns May 23rd, 2026! This is the second year we are running BSides Goldie and we are expanding the conference for 2026
020
6mile @6mile.githax.com · 01/02/2026
Heya @steipete.me can you do something about malicious skills in your ClawHub registry? Last night, one user published 200 malicious skills. I am tracking a dozen threat actors all publishing multiple malicious skills into this registry, and I've emailed you about all of them, but got crickets back
011
6mile @6mile.githax.com · 01/02/2026
Some of the most popular packages on the OpenClaw official registry ClawHub are malicious @openclaw-x.bsky.social
011
6mile @6mile.githax.com · 30/01/2026
FINALLY!!! github.com/microsoft/vs...
github.com
restore automatic task notification prompt, set automatic tasks to false by default by meganrogge · Pull Request #289947 · microsoft/vscode
fixes #287073 This restores the notification prompt that asks users to approve automatic tasks before they run, and changes the default behavior to be more secure. Default changed to off Permissio...
101
6mile @6mile.githax.com · 06/01/2026
Touche.
010
6mile @6mile.githax.com · 19/12/2025
Ooooohh, this looks legit!
010
6mile @6mile.githax.com · 17/12/2025
Another day, and another @hacker0x01.bsky.social "researcher" ganking people's AWS keys in a public NPM package (plugin-senna). 🤦‍♀️
000
6mile @6mile.githax.com · 15/12/2025
Bug bounty peeps, yo
010
6mile @6mile.githax.com · 15/12/2025
As an Australian, my heart hurts today.
000
Reposted by 6mile
Absolute AppSec @absoluteappsec.bsky.social · 02/12/2025
We have a special episode of @absoluteappsec.bsky.social today with Paul McCarty @6mile.githax.com who will help us make sense of the last few weeks of npm news. So join Paul @sethlaw.bsky.social and @cktricky.bsky.social at 12 Noon ET here: www.youtube.com/watch?v=UM4F...
Promotion for Absolute AppSec episode with Paul McCarty, taking place today Dec 2 at 12 Noon Eastern time. The show livestream link is provided here: https://www.youtube.com/watch?v=UM4Fq6Q_Qpg
012
6mile @6mile.githax.com · 18/11/2025
We knew it was coming, and now it's here: Dynamic payloads have been found in @npmjs.bsky.social packages. Ouch. 😦
011
6mile @6mile.githax.com · 14/11/2025
Noice! I think this is the first time my work has been covered by @bleepingcomputer.com
000
6mile @6mile.githax.com · 13/11/2025
I'm on @thehackernews.bsky.social again
110
6mile @6mile.githax.com · 12/11/2025
I've identified a new worm affecting NPM. I'm calling it "IndonesianFoods" based on its internal dictionary. The intent is to generate assets on the Tea Protocol blockchain. It's dumb, but it's MASSIVE! Check the link 👉 sourcecodered.com/indonesianfo... @npmjs.bsky.social @github.com
001
6mile @6mile.githax.com · 05/11/2025
I suspect a lot of full time BB peeps are doing the same
000
6mile @6mile.githax.com · 23/10/2025
I like the one-two combo you got going there picklerick
110
6mile @6mile.githax.com · 16/10/2025
Don't let AI write your payloads for you if you don't know what you're doing. Otherwise, you might end up publishing your API keys, environment variables, and identity to @npmjs.bsky.social
001
6mile @6mile.githax.com · 08/10/2025
Want to sniff out private bug bounty programs? If you monitor OSV for new malicious packages, you'll get some great intel. Today's example: @npmjs.bsky.social user Paastha published 6 packages targeting @vercel.com. But wait, they don't have a BB program?! Or do they.... 😮💥
010
6mile @6mile.githax.com · 08/10/2025
Tell me that @v0.dev has a bug bounty program without telling me they have a bug bounty program. #dependencyconfusion #maliciouspackage
011
6mile @6mile.githax.com · 07/10/2025
Heya homie, that ain't gonna work.
000
6mile @6mile.githax.com · 30/09/2025
Yes, thanks for follow up
010
6mile @6mile.githax.com · 28/09/2025
I need to talk to someone in the @reversinglabs.com detection team. Anyone in my network got an intro?
211
6mile @6mile.githax.com · 20/09/2025
I gave a talk at the FIRST CTI conference in Berlin earlier this year. Here's my presentation in its entirety. www.youtube.com/live/j23OubE...
youtube.com
YouTube
Share your videos with friends, family, and the world
000
6mile @6mile.githax.com · 17/09/2025
021
6mile @6mile.githax.com · 16/09/2025
Thanks mate! Great post pulling the thread.
010
6mile @6mile.githax.com · 28/08/2025
000
6mile @6mile.githax.com · 14/08/2025
Impressed with the Tenable One CSPM demo at the #Tenable #BlackHat booth. Blends vulnerability scanning with cloud security + ASPM features via IaC scanning and Git integrations. Worth checking if you're comparing cloud security solutions: bit.ly/4mbhg3e #BlackHat2025 #CloudSec
bit.ly
Tenable Cloud Security (CNAPP)
Reduce cloud risk and exposure from faulty configurations and entitlements with our cloud-native application protection platform (CNAPP), Tenable Cloud Security.
010
6mile @6mile.githax.com · 09/08/2025
See me at 11 am today on the #DEFCON Creator State 4 (room 228). I'm super excited for this, and a big "thank you!" to the #AdversaryVillage team! #hackersummercamp @github.com
010
6mile @6mile.githax.com · 01/08/2025
Yeah mate, i’ll be there all week.
010
6mile @6mile.githax.com · 31/07/2025
AI has written its first malicious package! I found an NPM package named @kodane/patch-manager that deploys a well-written persistent JavaScript crypto drainer. Here's the thing: I'm pretty sure Claude wrote it! Check out my post: getsafety.com/blog-posts/t... @anthropic.com @npmjs.bsky.social
getsafety.com
Threat actor uses AI to create a better crypto wallet drainer
Safety’s malicious package detection identified a malicious package that appears to have been written by Claude AI
110
6mile @6mile.githax.com · 17/07/2025
The apocalypse is upon us!
000
6mile @6mile.githax.com · 14/07/2025
I'm the first presentation for Adversary Village at @defcon.bsky.social. See me talk about open-source malware at 11 am on Saturday, August 9, in room 228 (creator stage 4)
020
6mile @6mile.githax.com · 06/07/2025
Heya @virginaustralia.bsky.social I just tried to buy tickets for $6903 as advertised, but turns out it's a bait & switch. Real price: $11,617. VA support blames it on "website latency" but that price still on site. Wonder what Australian ACCC will make of VA advertising fares that don't exist?
121
6mile @6mile.githax.com · 09/05/2025
110
6mile @6mile.githax.com · 02/04/2025
You can't make this shit up! The NIST NVD database has been down all day, so no one can look up CVEs via NVD. @shodanhq.bsky.social reports that one of the two ec2 instances serving up the NVD website reports a "402 Payment Required". Did DOGE dipshits break our national vulnerability database?!
110
6mile @6mile.githax.com · 08/03/2025
this might be an attempt to lock out the original developer right? We see that quite often in IR when the bad guy delete's original MFA device and adds a new one, effectively killing the legitimate users access.
000
6mile @6mile.githax.com · 18/02/2025
on it
010
6mile @6mile.githax.com · 18/02/2025
Can u dm me the url? I’ll take a look at it and tell u what it’s doing.
110
6mile @6mile.githax.com · 17/02/2025
New infostealer targets Exodus crypto wallets. The author wrote this malware in a little-known language to evade detection. Read my write-up here: sourcecodered.com/npm-package-...
sourcecodered.com
NPM package targeting crypto wallets uses new language to evade detection
A new software supply chain attack is targeting Exodus wallet files with a new custom malware that uses a unique evasion technique
010
6mile @6mile.githax.com · 11/02/2025
I wrote a post about the 3 most common myths I run into when talking to developers or infosec teams about malicious packages. Devs aren't familiar with malicious packages & security teams assume that existing security tools will find malware (spoiler: they don't). sourcecodered.com/three-myths-...
sourcecodered.com
3 myths about npm based threats
Npm-based threats are not well-understood, so I wrote a blog post addressing the 3 most common "myths" that I see from with engineering teams
041
6mile @6mile.githax.com · 28/01/2025
I've identified an NPM package named "arcus-cmd-utils" that deploys a Chrome-based infostealer to infected computers. You can read my blog post complete with technical details and IOCs. @npmjs.bsky.social @github.com #softwaresupplychain #devsecops sourcecodered.com/malicious-ar...
sourcecodered.com
Malicious NPM package infects developers with new infostealer malware
A malicious package named arcus-cmd-utils was published January 12, 2025 to npm registry which deploys a Windows based infostealer malware
021
6mile @6mile.githax.com · 19/01/2025
Oh wait, I thought you were talking about NPM
010
6mile @6mile.githax.com · 19/01/2025
Legit
100
6mile @6mile.githax.com · 14/01/2025
Yeah the HN thing was nice surprise
010
6mile @6mile.githax.com · 14/01/2025
My blog post is top spot on Hackernews! Woot! @hackernewsbot.bsky.social #softwaresupplychain
250
6mile @6mile.githax.com · 14/01/2025
Quickest turnaround in MONTHS from NPM as they've taken down the marked-cs and marked-ps malicious packages in less than a day! Woot! @npmjs.bsky.social #softwaresupplychain #npm
010
6mile @6mile.githax.com · 13/01/2025
Two malicious packages were published to the NPM registry named "marked-cs" & "marked-ps". They take advantage of naming inconsistencies in the popular marked-js library & deploy modified gh0strat implants when you install the malicious packages. @npmjs.bsky.social sourcecodered.com/npm-packages...
sourcecodered.com
Malicious NPM packages target marked-js library
Two malicious packages were published to the NPM registry on January 7th. These packages target legitimate marked-js users to deploy malware.
020