Sign in

ReversingLabs

@reversinglabs.com
133 followers 85 following 334 posts

ReversingLabs is the trusted name in file and software security. RL - Trust Delivered.

PostsRepliesMedia
ReversingLabs @reversinglabs.com · 24/09/2026
The patching window has collapsed. Mean time to exploit crossed zero in 2024, and AI can turn disclosed vulnerabilities into working exploits in ~10-15 minutes. A patch can now be an answer key for the attacker. New analysis from ReversingLabs: www.reversinglabs.com/resources/th...
reversinglabs.com
AI and Patch Security: The Patch Is the Attack Payload | ReversingLabs
See how AI is collapsing the exploit window, turning patches into attacker intelligence, and forcing security teams to rethink software risk.
000
ReversingLabs @reversinglabs.com · 22/09/2026
ReversingLabs researchers uncovered a malicious npm package posing as an authorized Twilio bug bounty tool. The package targeted Twilio Account SIDs and Auth Tokens and exfiltrated them via webhook. We reported it to npm. It was removed within an hour. ⬇️ www.reversinglabs.com/blog/malicio...
reversinglabs.com
Malicious npm campaign targets developers integrating Twilio | RL Blog
The package poses as a security tool targeting developers looking to integrate Internet-based apps with telecom networks using Twilio.
100
ReversingLabs @reversinglabs.com · 03/09/2026
"Agents are only going to be as smart as the context they can reason on." ExtraHop's Kanaiya Vasani explains why the agentic SOC is an architecture problem before it's a model problem: www.reversinglabs.com/blog/how-to-... #CyberSecurity
reversinglabs.com
How to build effective agentic SOCs: What you need to know | RL Blog
ExtraHop's Kanaiya Vasani unpacks the concept of the agentic SOC — and how the Agentic SOC Alliance is working to build them out.
000
ReversingLabs @reversinglabs.com · 28/08/2026
A behavioral verdict tells you what a process did. It doesn't tell you what the file is, what else it can do, or who else is running it. Spectra Analyze gives every CrowdStrike Falcon detection a second opinion that doesn't expire. Learn more: www.reversinglabs.com/blog/extend-... #SecOps
reversinglabs.com
Extend CrowdStrike Falcon With Permanent Intelligence | RL Blog
ReversingLabs built a Spectra Analyze integration with CrowdStrike Falcon. The connector is available now as part of Spectra Analyze v9.6.0.
000
ReversingLabs @reversinglabs.com · 28/08/2026
3/ Delivery is the boring part: ClickFix, ClearFake, and SEO-poisoned pages impersonating open-source tools. Full breakdown and IoCs: reversinglabs.com/blog/infoste... #ThreatIntel
reversinglabs.com
Infostealers highlight malware-as-a-service trend | RL Blog
Aurastealer, ACRStealer, and RemusStealer, a new potential LumaStealer variant, show MaaS in action. Here's what you need to know.
000
ReversingLabs @reversinglabs.com · 28/08/2026
2/ AuraStealer added virtualization this summer, going from ~600KB to 10MB to slow analysis. Remus uses EtherHiding to stash C2 domains in Ethereum smart contracts. ACRStealer rebranded as Amatera and kept running.
100
ReversingLabs @reversinglabs.com · 28/08/2026
1/ Three infostealer families, one business model. AuraStealer, ACRStealer/Amatera, and Remus Stealer are all sold as malware-as-a-service, and ReversingLabs tracked all three across July and August.
100
ReversingLabs @reversinglabs.com · 17/07/2026
When the user becomes the vulnerability, new threats emerge. No exploits, just trust breaches. Dive into our #ClickFix report by Toni Dujmović for more insights! #CyberAwareness #ReversingLabs youtube.com/shorts/MHm4K...
youtube.com
ClickFix: The Fake CAPTCHA That Hijacks Your Clipboard
YouTube video by ReversingLabs
000
ReversingLabs @reversinglabs.com · 14/07/2026
📢 New ReversingLabs research: Copy, Paste, Compromise: The Tale of ClickFix The complete #ClickFix attack chain, the MaaS economy behind it, and an open-source #YARA rule validated against 4K+ samples — 123 of them lures that evaded every #Antivirus engine. 👇 www.reversinglabs.com/clickfix
reversinglabs.com
ClickFix Threat Report: Copy, Paste, Compromise | ReversingLabs | ReversingLabs
Original RL research on ClickFix: the attack chain, the MaaS economy behind it, and the YARA detection strategy that catches what AV and EDR miss.
000
ReversingLabs @reversinglabs.com · 02/07/2026
Here's how the category evolved — and what it means for your CI/CD pipeline, and your next release. www.reversinglabs.com/blog/gartner... #SoftwareSupplyChain
reversinglabs.com
This Report from Gartner Defines the Software Supply Chain Security Market | RL Blog
Explore the new Gartner® Magic Quadrant™ for software supply chain security and learn why ReversingLabs is recognized.
000
ReversingLabs @reversinglabs.com · 02/07/2026
Gartner just defined a new market — and that matters more than it sounds. ReversingLabs was named a Visionary in the new Gartner® Magic Quadrant™ for the category we helped build. www.reversinglabs.com/blog/gartner... #SoftwareSupplyChain
reversinglabs.com
This Report from Gartner Defines the Software Supply Chain Security Market | RL Blog
Explore the new Gartner® Magic Quadrant™ for software supply chain security and learn why ReversingLabs is recognized.
101
ReversingLabs @reversinglabs.com · 25/06/2026
The question is no longer "Is this software secure?" It's "Can this software be trusted?" Trust should be verified, not assumed. Download your copy of the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security report here: www.reversinglabs.com/2026-gartner...
010
ReversingLabs @reversinglabs.com · 16/06/2026
npm v12 turns off install script execution by default — the vector Shai-Hulud, Mini Shai-Hulud, and Miasma all relied on. Security experts break down what it fixes and what attackers are already doing instead: www.reversinglabs.com/blog/npm-v12...
reversinglabs.com
npm v12 blocks install scripts: What it means for software supply chain security | RL Blog
By disabling install scripts by default, it closes the vector worms like Shai-Hulud rely on. Here's what the update fixes — and what it doesn't.
000
ReversingLabs @reversinglabs.com · 09/06/2026
Threat actors are using #TikTok & #Instagram tutorials to deliver #Vidarstealer. One video hit 100K views and 1,700 saves — because attackers know which metrics move the algorithm. Research breakdown + IoCs: www.reversinglabs.com/blog/social-... #SocialEngineering #Phishing
reversinglabs.com
Phishing Attacks Leverage TikTok, Instragram Reels | RL Blog
RL has discovered two social engineering attack techniques targeting users via short-form videos. Here’s how they work.
000
ReversingLabs @reversinglabs.com · 03/06/2026
48,000 CVEs in 2025. Only 58 posed a real, exploitable threat to enterprise supply chains. "Patch everything" is mathematically dead. The signal that matters: malware, tampering, exposed secrets. Go from noise to signal: www.reversinglabs.com/blog/noise-t... #AppSec #SoftwareSupplyChainSecurity
reversinglabs.com
CVE noise drowns out software supply chain threats | RL Blog
48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.
000
ReversingLabs @reversinglabs.com · 01/06/2026
Full technical analysis, IoC table (31 unique "index.js" SHA-256 hashes), and safe version guidance are available in ReversingLabs’ latest blog: www.reversinglabs.com/blog/31-red-...
reversinglabs.com
31 Red Hat npm packages backdoored in 72 seconds | RL Blog
RL has discovered a new supply chain attack affecting 9.8M total downloads across Red Hat's Hybrid Cloud Console JavaScript ecosystem.
010
ReversingLabs @reversinglabs.com · 01/06/2026
Rotate all credentials, tokens, SSH keys, and secrets accessible from that environment. Audit your lock files for the exact malicious version pins and block the SHA-256 hashes in your artifact proxy.
100
ReversingLabs @reversinglabs.com · 01/06/2026
RECOMMENDATIONS If you ran "npm install" on June 1 between approximately 10:54–10:56 UTC and any of these packages appear in your dependency tree — directly or transitively — treat the build environment as compromised.
100
ReversingLabs @reversinglabs.com · 01/06/2026
Clean N+1 versions have been published by legitimate maintainers for all 31 packages. The malicious versions have since been removed from npm.
100
ReversingLabs @reversinglabs.com · 01/06/2026
Affected packages include widely used components: "frontend-components" (1.35M downloads), "frontend-components-utilities" (1.49M), "types" (1.28M), "rbac-client" (942K), "frontend-components-config-utilities" (874K), and "frontend-components-config" (788K), among others.
100
ReversingLabs @reversinglabs.com · 01/06/2026
SCOPE OF COMPROMISE The 31 packages span two separate GitHub source repositories ("RedHatInsights/frontend-components" and "RedHatInsights/javascript-clients"), confirming this was a scope-level npm credential compromise — not a per-repository breach.
100
ReversingLabs @reversinglabs.com · 01/06/2026
The attacker generated 31 individually tailored payloads — each with its own rotation value, AES key, and IV — giving every "index.js" a unique SHA-256 hash.
100
ReversingLabs @reversinglabs.com · 01/06/2026
The surgical precision confirms automated tooling. The obfuscation uses two stacked layers: a ROT-N caesar cipher decodes a first-stage JavaScript string, which then uses Node.js's built-in "crypto" module to perform AES-128-GCM decryption of the final payload.
100
ReversingLabs @reversinglabs.com · 01/06/2026
WHAT HAPPENED Every malicious version follows the same two-file modification pattern: "package.json" gained a "preinstall" hook pointing to "index.js," and "index.js" — the package's own entry point — was fully replaced with an obfuscated dropper. No other files were touched.
100
ReversingLabs @reversinglabs.com · 01/06/2026
On June 1, an attacker published malicious versions of 31 packages in a 72-second automated scripted push — affecting approximately 9.8 million total downloads across Red Hat's Hybrid Cloud Console JavaScript ecosystem.
100
ReversingLabs @reversinglabs.com · 01/06/2026
🚨 Supply Chain Attack Alert! 🚨 31 @redhat-cloud-services hashtag#npm packages backdoored in 72 seconds! ReversingLabs has confirmed a large-scale, coordinated supply chain attack targeting the "@redhat-cloud-services" npm scope.
100
ReversingLabs @reversinglabs.com · 27/05/2026
Megalodon compromised GitHub Actions YAML files across dozens of repos — base64-encoded credential stealer, C2 on RouterHosting LLC. RL retrohunted to a related campaign 2 weeks earlier. Same C2 pattern. Same adversary. IOCs + YARA rule published: hubs.ly/Q04hVW-v0
hubs.ly
Researcher's Notebook: Hunting Megalodon Fossils | RL Blog
Analyzing C2 responses from compromised GitHub Actions linked a current threat to an earlier one, showing the value of retrohunting.
000
ReversingLabs @reversinglabs.com · 12/05/2026
RL documented 163 samples of the Dirty Frag Linux exploit (formerly Copy Fail), active malware — and developed YARA rules for identification. Patch the kernel. Run the queries. Deploy the rules. The detection gap is now. www.reversinglabs.com/blog/dirtyfr...
reversinglabs.com
How Dirty Frag rose from the Linux exploit Copy Fail | RL Blog
RL researchers documented 163 samples tied to CVE-2026-31431, identified active malware adoption — and developed YARA rules to identify them.
010
ReversingLabs @reversinglabs.com · 05/05/2026
Is frontier #AI risk keeping your #AppSec team up at night? Doug Levin shares the facts on #ClaudeMythos. Doug also lays out the case for why a layered #AppSec framework is essential — and what it should look like. 👇 www.reversinglabs.com/blog/how-myt...
reversinglabs.com
How Claude Mythos changes the application security calculus | ReversingLabs
Here are the facts on Mythos — and why your organization must adopt a layered security framework to match the new frontier models.
000
ReversingLabs @reversinglabs.com · 04/05/2026
A new class of #AI-derived threats is raising red flags: #MCP post-deployment drift ("rug pull") attacks. They exploit trust of agents over time rather than at the initial point of compromise, which requires deeper visibility. Here's what you need to know. hubs.ly/Q04fhLR30
hubs.ly
MCP client rug-pull attack worries mount for AppSec | ReversingLabs
This class of AI tool supply chain attack highlights how trust of agents can be exploited by threat actors.
000
ReversingLabs @reversinglabs.com · 28/04/2026
Malware is evolving—and targeting AI workflows. Our research on the PromptMink campaign shows how attackers are abusing AI coding agents like Claude to deliver crypto-stealing malware. This isn’t just prompt injection. It’s supply chain risk in a new form. Read: www.reversinglabs.com/blog/claude-...
reversinglabs.com
Claude adds PromptMink malicious dependency to crypto agent | ReversingLabs
The malicious npm package has evolved into a dependency that allows attackers to access users’ crypto wallets and funds.
030
ReversingLabs @reversinglabs.com · 22/04/2026
Attackers hid their changes in files promising to improve extensions #MCP server support, but fetch a malicious payload from an impostor commit on @github.com linked to the #cx-bot-gh public service account. Our threat research team is monitoring the situation. secure.software/vscode/packa...
000
ReversingLabs @reversinglabs.com · 22/04/2026
It looks like #TeamPCP has again compromised #Checkmarx #VSCode extensions and #Docker images. Newly published VSCode extensions checkmarx.cx-dev-assist (1.17.0 & 1.19.0) and checkmarx.ast-results (2.63.0 & 2.66.0) contain malicious code. secure.software/vscode/packa...
Report: threats detected in Checkmarx Developer Assist - image from secure.software.
221
ReversingLabs @reversinglabs.com · 15/04/2026
Try Spectra Assure Community yourself - for FREE: secure.software/user/signup
secure.software
Sign up | ReversingLabs Spectra Assure Community
Sign up | ReversingLabs Spectra Assure Community
000
ReversingLabs @reversinglabs.com · 15/04/2026
It’s no secret modern #AppDev relies on #OpenSource — what’s catching up is how teams secure it. RL’s free Spectra Assure Community helps teams make smarter decisions about the software they use and ship. 👇 www.reversinglabs.com/blog/why-rl-...
reversinglabs.com
Securing the Village: Why RL Built Spectra Assure Community | ReversingLabs
ReversingLabs built it to help development and AppSec teams secure open source dependencies, detect malware — and prevent supply chain attacks.
120
ReversingLabs @reversinglabs.com · 14/04/2026
High-end AppSec isn’t just for the Fortune 500. Spectra Assure Community gives devs, AppSec teams & OSS maintainers pro-grade supply chain security insights — without the cost or complexity. Move beyond blind trust 👉 secure.software/user/signup
000
Reposted by ReversingLabs
Cyber Threat Alliance @cyberalliance.bsky.social · 10/04/2026
CTA Member @reversinglabs.com on a fake recruiter campaign: www.reversinglabs.com/blog/graphal... #cybersecurity #scam #fakerecruiter
reversinglabs.com
Graphalgo fake recruiter-test campaign respawned | ReversingLabs
NK threat actors targeting crypto developers are back with an LLC and new techniques to hide malware. Here's RL's analysis.
011
ReversingLabs @reversinglabs.com · 09/04/2026
🚨 New RL #ThreatResearch: The #Graphalgo fake developer recruiter interview campaign is back. RL researchers have uncovered a broader network of fake companies tied to this fake recruiter operation — plus new attacker techniques. Read what the RL team found: www.reversinglabs.com/blog/graphal...
reversinglabs.com
Graphalgo fake recruiter-test campaign respawned | ReversingLabs
NK threat actors targeting crypto developers are back with an LLC and new techniques to hide malware. Here's RL's analysis.
000
ReversingLabs @reversinglabs.com · 03/04/2026
The axios supply chain attack should be front an center for #AppSec teams given it's wide reach. Here's RL's immediate-response checklist — and best practices for ongoing defense. Also learn how RL’s xBOM and Spectra Assure Community can help. 👇 www.reversinglabs.com/blog/axios-a...
reversinglabs.com
Axios supply chain attack: How AppSec teams should respond | ReversingLabs
Here's an incident-response checklist and ongoing best practices. Plus: How RL’s xBOM and Spectra Assure Community can help.
000
ReversingLabs @reversinglabs.com · 02/04/2026
At #RSAC, JPMorgan Chase CISO Patrick Opet revisited third-party risk — and the supplier changes that followed. Is your organization learning the lesson on “trust debt”? Learn how to move beyond blind trust: www.reversinglabs.com/blog/opet-jp...
reversinglabs.com
How JPMorgan Chase tackles third-party software ‘trust debt’ | ReversingLabs
JPMC CISO Patrick Opet discussed his open letter on third-party software risk — and the changes suppliers have made since.
000
ReversingLabs @reversinglabs.com · 31/03/2026
The compromise spread to PyPI and NuGet ecosystem through usage of JSII modules inside versions 0.0.194 of the jjrawlins-cdk-iam-policy-builder-helper packages. Packages depend on compromised versions of axios npm package. secure.software/pypi/package... secure.software/nuget/packag...
secure.software
jjrawlins-cdk-iam-policy-builder-helper@0.0.194 - PyPI | ReversingLabs Spectra Assure Community
Supply chain risk analysis for jjrawlins-cdk-iam-policy-builder-helper@0.0.194. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
010
ReversingLabs @reversinglabs.com · 31/03/2026
🚨 RL Research Alert! Look out for the compromised versions 1.14.1 and 0.30.4 of axios npm package with almost 11 billion downloads. secure.software/npm/packages...
secure.software
axios@1.14.1 - npm | ReversingLabs Spectra Assure Community
Supply chain risk analysis for axios@1.14.1. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
100
ReversingLabs @reversinglabs.com · 27/03/2026
It is the latest victim in the ongoing TeamPCP supply chain campaign. Previous victims include Trivy, Checkmarx and LiteLLM.Ultimate goal is exfiltration of cloud secrets like observed in previous attacks. Malicious code is added to telnyx/_client.py file. New C2 server is 83[.]142.209.203
000
ReversingLabs @reversinglabs.com · 27/03/2026
Look out for compromised versions 4.87.1 and 4.87.2 of telnyx PyPI package with more than 3.75 million downloads. secure.software/pypi/package...
secure.software
telnyx@4.87.2 - PyPI | ReversingLabs Spectra Assure Community
Supply chain risk analysis for telnyx@4.87.2. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
100
ReversingLabs @reversinglabs.com · 24/03/2026
📢 Just dropped: New RL research! 👻 Ghost campaign returns via malicious #npm packages ⚠️ Phishes sudo passwords + hides behind fake install logs 🔍 www.reversinglabs.com/blog/npm-fak... 🛡️ Ask us about it — + Spectra Assure Community — at Booth #4328 #RSAC2026
reversinglabs.com
Malicious npm packages use fake install logs to load RAT | ReversingLabs
The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.
000
ReversingLabs @reversinglabs.com · 22/03/2026
Security Advisory: our research team is tracking threat actor #TeamPCP, who hacked the #Trivy supply chain and infected over 140 npm packages with self-propagating malware #CanisterWorm. View our platform's analysis of a known infected package here: secure.software/npm/packages...
secure.software
@teale.io/eslint-config@1.8.9 - npm | ReversingLabs Spectra Assure Community
Supply chain risk analysis for @teale.io/eslint-config@1.8.9. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.
000
Reposted by ReversingLabs
Cyber Threat Alliance @cyberalliance.bsky.social · 13/03/2026
"Ambiguous package names & fragmented tracking methods leave organizations vulnerable to sophisticated supply chain attacks. By demanding PURLs in your SBOMs, you enforce a strict standard of visibility and accountability" www.reversinglabs.com/blog/why-you... #cybersecurity #SBOM @reversinglabs.com
reversinglabs.com
How to Make Your SBOMs Actionable with PURLs | ReversingLabs
Package URLs give software components an exact address to improve vulnerability matching, which reduces alert fatigue and simplifies compliance.
011
ReversingLabs @reversinglabs.com · 05/03/2026
BSIMM16 reinforces that #AIcoding is the new reality — and it will further destabilize #softwaresupplychainsecurity. So step up your #AppSec. 👇 www.reversinglabs.com/blog/bsimm16...
reversinglabs.com
BSIMM16 confirms it: AI redefines the AppSec landscape | ReversingLabs
AI coding is the new reality — and it will further destabilize software supply chain security. So step up your AppSec.
000
ReversingLabs @reversinglabs.com · 26/02/2026
🚨 RL researchers discovered a malicious package impersonating a legitimate Stripe package on #NuGet — marking a move away from blockchain-related targets while staying focused on financial development tools. Read here: www.reversinglabs.com/blog/malicio...
reversinglabs.com
Malicious NuGet package targets Stripe | ReversingLabs
In this latest incident, threat actors target developers with a bogus package — a shift away from cryptocurrency development targets.
010
ReversingLabs @reversinglabs.com · 19/02/2026
ReversingLabs' Ashlee Benge shares how to use YARA retrohunting for detection engineering by leverageing RL's dynamic analysis of "pkr_mtsi" for defense in Spectra Analyze. 👉 hubs.ly/Q043qJY-0 #yararules #detectionengineering #malwareanalysis
hubs.ly
How to Use YARA Retrohunting for Detection Engineering | ReversingLabs
Learn how to leverage ReversingLabs’s dynamic analysis of <em>pkr_mtsi</em> for defense using YARA Rules in Spectra Analyze.
000