Sign in

boredchilada

@cyfar.ca
77 followers 6 following 2.6K posts

I sheer alpacas and try to defend the internet from malware, minimal memes, mostly biznez Cyfar.ca @cyfar@infosec.exchange

PostsRepliesMedia
boredchilada @cyfar.ca · 05/09/2026
30 day distribution of wp2shell
Distribution
000
boredchilada @cyfar.ca · 27/07/2026
#wp2shell
wp2shell
000
boredchilada @cyfar.ca · 08/06/2026
more shai! Package Version(s) Publisher tiktoken-mcp 0.13.1, 0.13.2 — <-- LLM INJECTION instructor-mcp 1.15.2, 1.15.3 — langchain-core-mcp 1.4.2, 1.4.3 — openai-mcp 2.41.1, 2.41.2 — orchestr8-platform 3.3.2 Orchestr8 Team ray-mcp-server 0.2.1 Vaskin Kissoyan @socket.dev
010
boredchilada @cyfar.ca · 07/06/2026
Another one rlask==3.1.4-7 tlask== 3.1.4 same aes encryption (128) just rot 20 this time. pypi.org/user/elitexp/ @socket.dev
100
boredchilada @cyfar.ca · 06/06/2026
@socket.dev Seems like theres an active shai hulud across 27 packages on pypi? 99.9% sure. coolbox, funcdesc, ... Weize Xu <vet.xwz@gmail.com>
120
boredchilada @cyfar.ca · 31/05/2026
we've been seeing a lot of docker attacks, more and more are carrying what looks like agentic command nomenclature you see when you use tools like Claude code. Another attack involved a script being dropped onto every docker container. new engagements coming soon detailing these
000
boredchilada @cyfar.ca · 27/05/2026
thanks bing claudecode(.)us(.)com -> setup-code(.)com #malware #socialengineering #bing #brocomeon #didntfallforittho #claude
100
boredchilada @cyfar.ca · 19/05/2026
hi bb ioc:34.70.205[.]211 #xmrig #cryptominer
000
boredchilada @cyfar.ca · 18/05/2026
whats up with this recent attack chain uptick? attackers are rotating them or something X) #malware #webdav #ntlm
100
boredchilada @cyfar.ca · 03/05/2026
AI agent? or Vibes? Seen on Docker API sensors, @greynoise.io spotted it too, not sure what they saw. 41.249.87.)223 #Threatintel #docker #AI #LLM
000
boredchilada @cyfar.ca · 01/02/2026
clickfix / clearfake hoteldelpaseocampeche[.]com/ https[:]//shield.pages[.]dev/js/shield[.]min[.]js c2'ish : https[:]//api[.]cdn0v3[.]com/api/v1 dropper/loader: https[:]//gateway9[.]pages[.]dev/tom[.]tar builds payload via csc
000
boredchilada @cyfar.ca · 07/01/2026
hmmmm ...
000
boredchilada @cyfar.ca · 19/12/2025
Okay, who let AI into @sophossecurity.bsky.social webservers?
000
boredchilada @cyfar.ca · 09/12/2025
some weird lures with an obvious domain name? microsoft. myluresevil .win
000
boredchilada @cyfar.ca · 02/11/2025
Seems like redishell is being exploited now seen in the wild. 196.251.70.)215 401120 #redishell #exploit #reverseshell
010
boredchilada @cyfar.ca · 25/09/2025
Hackers be like
000
boredchilada @cyfar.ca · 30/07/2025
Malware if anyone is interested: 1337x[.]to/torrent/6339414/Image-Li… drops aurotun/monsterv2 via nsis C2s: 198.251.84[.]224 & 196.251.72[.]174 port:7172
000
boredchilada @cyfar.ca · 18/06/2025
000