#MaliciousCode

PUPUWEB Blogpupuweb
2024-11-16

🚨 Malicious commits target GitHub projects! A Texas researcher claims someone is impersonating him to sabotage his reputation. 🛑👨‍💻

Inautiloinautilo
2024-06-06
〇 ṃѧяȗṿєяṡє 〇maruverse@infosec.exchange
2024-04-03

Article about XZ: As for which nation, Raiu names the usual suspects: China, Russia, North Korea. He says it’s still too early to know the true culprit.

Why is it never: United States of America. Because I can assure you, they are quite the player when it comes to building backdoors and other infiltration tech. Somehow they're always kept from the list.

Maybe they were less in need of it though, since they already have their ways by official means

#XZ #hack #maliciouscode #cybersecurity

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-09-29

"🤖 Dependabot Impersonation: A New Veil for Malicious Code Commits 🕵️"

In a recent revelation, Checkmarx's research team uncovered a sophisticated attack where threat actors impersonated Dependabot, GitHub's automated dependency management tool, to inject malicious code into hundreds of GitHub repositories. The attackers fabricated commit messages to appear as if Dependabot made them, thus camouflaging their malicious activity. This malicious code aimed to exfiltrate GitHub project secrets to a rogue server and modify JavaScript files to steal end-user passwords. The attackers seemed to have leveraged stolen GitHub personal access tokens, bypassing 2FA, to carry out this campaign. This incident underscores the escalating sophistication in supply chain attacks, urging developers to exercise heightened vigilance even in trusted platforms like GitHub.

Source: Checkmarx Blog

Tags: #CyberSecurity #GitHub #Dependabot #SupplyChainAttack #MaliciousCode #InfoSec

Authors: Guy Nachshon, Jossef Harush Kadouri, Tzachi Zornshtain, Aviad Gershon

2020-07-29

OkCupid Security Flaw Threatens Intimate Dater Details - Attackers could exploit various flaws in OkCupid's mobile app and webpage to steal victims' sensit... more: threatpost.com/okcupid-securit #crossoriginresourcesharing #vulnerabilities #okcupidsecurity #maliciouscode #mobileappflaw #vulnerability #securityflaw #websecurity #datingapp #okcupid #hack

2019-07-27

No matter how many times I share to Mastodon from YouTube, it won't put it at the top of the share-to list. It actually keeps shuffling it around, making it more of a pain to locate.
#MaliciousCode
#Algorithms

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst