Sign in

Christophe Tafani-Dereeper

@christophetd.fr
1.5K followers 120 following 91 posts

Cloud and container security • Security research and open source at Datadog 🇨🇭🇫🇷 christophetd.fr

PostsRepliesMedia
Christophe Tafani-Dereeper @christophetd.fr · 10/07/2026
Interesting backdoor in an npm package. Analyzing the timezone in git commit metadata shows this is likely a compromised maintainer account
000
Christophe Tafani-Dereeper @christophetd.fr · 31/03/2026
I wrote up an analysis of the Axios compromise: securitylabs.datadoghq.com/articles/axi... Crazy how while researchers were filing issues to report the compromise, the attacker was deleting them in real time using the maintainer's GitHub access!
033
Christophe Tafani-Dereeper @christophetd.fr · 12/02/2026
I asked Claude (Opus 4.6) and Codex (GPT-5.3) to each generate a simple LinkedList implementation in Java. Then I asked Claude to pick the better one. No hesitation: "The Codex version is better" 🤔 gist.github.com/christophetd...
The Codex version is better. The tail pointer is the defining difference — it shows a stronger understanding of linked list design. O(1)
   append is the whole reason you'd use a linked list over an array in many scenarios, and the Claude version gets that wrong. The Codex
  version is also cleaner structurally (shared nodeAt helper, no redundant initializations).
070
Christophe Tafani-Dereeper @christophetd.fr · 28/07/2025
Getting ready for DEF CON next week! ✅ Slides ✅ Demos ✅ Custom shirt designed for the occasion
020
Christophe Tafani-Dereeper @christophetd.fr · 18/07/2025
Looks like the maintainer of a number of highly-popular npm packages was phished through npnjs[.]com, and his access used to publish malicious versions of their packages x.com/JounQin/stat... www.linkedin.com/feed/update/... github.com/prettier/esl...
155
Christophe Tafani-Dereeper @christophetd.fr · 23/06/2025
Stratus Red Team AWS attack techniques are now mapped to the Threat Technique Catalog for AWS Stratus Red Team AWS attack techniques: stratus-red-team.cloud/attack-techn... Threat Technique Catalog by AWS: aws-samples.github.io/threat-techn...
072
Christophe Tafani-Dereeper @christophetd.fr · 10/06/2025
Solid way to start the week
1281
Christophe Tafani-Dereeper @christophetd.fr · 15/05/2025
👀
010
Christophe Tafani-Dereeper @christophetd.fr · 24/02/2025
L'ANSSI vient de sortir un rapport sur la menace dans les environnements cloud, en Français : www.cert.ssi.gouv.fr/uploads/CERT... Au programme : • Menaces ciblant les fournisseurs • Menaces ciblant les utilisateurs finaux • L'usage que les attaquants font du cloud @anssi-fr.bsky.social
031
Christophe Tafani-Dereeper @christophetd.fr · 22/01/2025
As an European, the term "deportation" is always painful to hear, especially on the topic of immigrants and political oponents (it doesn't have the same meaning as in French, but it's spelled the same)
100
Christophe Tafani-Dereeper @christophetd.fr · 16/12/2024
New research: We've been monitoring a threat actor publishing dozens of trojanized GitHub repositories targeting threat actors, leaking hundreds of thousands of credentials along the way securitylabs.datadoghq.com/articles/mut...
Overview of the attack flowOverview of how a large number of credentials were leakedClusters of fake GitHub profilesPhishing e-mail
02113
Christophe Tafani-Dereeper @christophetd.fr · 13/12/2024
I'll be at BSides London tomorrow, looking forward to it! Schedule looks amazing: cfp.securitybsides.org.uk/bsides-londo... cc @bsideslondon.bsky.social
070
Christophe Tafani-Dereeper @christophetd.fr · 05/12/2024
Supply-chain attack in the ultralytics PyPI package: github.com/ultralytics/... An attacker opened a pull request and pushed a commit with a malicious name, leading to CI code injection. They then backdoored versions 8.3.41 and 8.3.42 with code downloading a second-stage binary from GitHub
153
Christophe Tafani-Dereeper @christophetd.fr · 04/12/2024
Stratus Red Team v2.20.0 is now available, with great contributions from @flekyy90.bsky.social allowing you to reproduce AWS TTPs seen in the wild! ➔ Use GetFederationToken to generate temporary credentials ➔ Use SendSerialConsoleSSHPublicKey to pivot to EC2 instances github.com/DataDog/stra...
1149
Christophe Tafani-Dereeper @christophetd.fr · 04/12/2024
C2 is currently down
100
Christophe Tafani-Dereeper @christophetd.fr · 03/12/2024
Exclusive: The backdoor inserted in v1.95.7 adds an "addToQueue" function which exfiltrates the private key through seemingly-legitimate CloudFlare headers. Calls to this function are then inserted in various places that (legitimately) access the private key.
35232
Christophe Tafani-Dereeper @christophetd.fr · 21/11/2024
040
Christophe Tafani-Dereeper @christophetd.fr · 21/11/2024
the "previous third party" who left the web shell
020
Christophe Tafani-Dereeper @christophetd.fr · 21/11/2024
Great new feature in Terraform (v1.10.0 RC): ephemeral resources! Perfect when you need to retrieve credentials that you don't want to persist in the state. developer.hashicorp.com/terraform/la... Currently supports aws_lambda_invocation, aws_kms_secrets, and aws_secretsmanager_secret_version
1100
Christophe Tafani-Dereeper @christophetd.fr · 18/11/2024
November 2024 bluesky community vibes
040
Christophe Tafani-Dereeper @christophetd.fr · 11/05/2023
when I can automate a task
000
Christophe Tafani-Dereeper @christophetd.fr · 03/05/2023
"Hey, I wonder what's new in Ubuntu 22.04 LTS" *reads* *indistinct nervous laughter*
100