6mile's Avatar

6mile

@6mile.githax.com

Software Supply Chain Red Team. SourceCodeRED & SecureStack founder, dad, startup OG, snowboarder and hacker. Workin on GitHax tool in my spare time. github.com/6mile @eastsidemccarty from the bird site.

239
Followers
529
Following
71
Posts
23.08.2023
Joined
Posts Following

Latest posts by 6mile @6mile.githax.com

Post image Post image

Heya @steipete.me can you do something about malicious skills in your ClawHub registry? Last night, one user published 200 malicious skills. I am tracking a dozen threat actors all publishing multiple malicious skills into this registry, and I've emailed you about all of them, but got crickets back

01.02.2026 21:14 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

Some of the most popular packages on the OpenClaw official registry ClawHub are malicious
@openclaw-x.bsky.social

01.02.2026 12:19 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
restore automatic task notification prompt, set automatic tasks to false by default by meganrogge ยท Pull Request #289947 ยท microsoft/vscode fixes #287073 This restores the notification prompt that asks users to approve automatic tasks before they run, and changes the default behavior to be more secure. Default changed to off Permissio...

FINALLY!!!
github.com/microsoft/vs...

30.01.2026 22:46 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Touche.

06.01.2026 22:39 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Ooooohh, this looks legit!

19.12.2025 06:06 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Another day, and another @hacker0x01.bsky.social "researcher" ganking people's AWS keys in a public NPM package (plugin-senna). ๐Ÿคฆโ€โ™€๏ธ

17.12.2025 06:18 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Bug bounty peeps, yo

15.12.2025 05:09 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

As an Australian, my heart hurts today.

15.12.2025 02:23 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Promotion for Absolute AppSec episode with Paul McCarty, taking place today Dec 2 at 12 Noon Eastern time. The show livestream link is provided here: https://www.youtube.com/watch?v=UM4Fq6Q_Qpg

Promotion for Absolute AppSec episode with Paul McCarty, taking place today Dec 2 at 12 Noon Eastern time. The show livestream link is provided here: https://www.youtube.com/watch?v=UM4Fq6Q_Qpg

We have a special episode of @absoluteappsec.bsky.social today with Paul McCarty @6mile.githax.com who will help us make sense of the last few weeks of npm news. So join Paul @sethlaw.bsky.social and @cktricky.bsky.social at 12 Noon ET here: www.youtube.com/watch?v=UM4F...

02.12.2025 15:02 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

We knew it was coming, and now it's here: Dynamic payloads have been found in @npmjs.bsky.social packages.
Ouch. ๐Ÿ˜ฆ

18.11.2025 23:58 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Noice! I think this is the first time my work has been covered by @bleepingcomputer.com

14.11.2025 21:19 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I'm on @thehackernews.bsky.social again

13.11.2025 19:31 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

I've identified a new worm affecting NPM. I'm calling it "IndonesianFoods" based on its internal dictionary. The intent is to generate assets on the Tea Protocol blockchain.
It's dumb, but it's MASSIVE!
Check the link ๐Ÿ‘‰
sourcecodered.com/indonesianfo...
@npmjs.bsky.social @github.com

12.11.2025 23:30 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I suspect a lot of full time BB peeps are doing the same

05.11.2025 13:28 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

I like the one-two combo you got going there picklerick

23.10.2025 00:06 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Don't let AI write your payloads for you if you don't know what you're doing. Otherwise, you might end up publishing your API keys, environment variables, and identity to @npmjs.bsky.social

16.10.2025 22:41 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image Post image

Want to sniff out private bug bounty programs? If you monitor OSV for new malicious packages, you'll get some great intel. Today's example: @npmjs.bsky.social user Paastha published 6 packages targeting @vercel.com. But wait, they don't have a BB program?! Or do they.... ๐Ÿ˜ฎ๐Ÿ’ฅ

08.10.2025 21:24 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Tell me that @v0.dev has a bug bounty program without telling me they have a bug bounty program.
#dependencyconfusion #maliciouspackage

08.10.2025 08:38 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Heya homie, that ain't gonna work.

07.10.2025 09:31 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Yes, thanks for follow up

30.09.2025 18:41 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I need to talk to someone in the @reversinglabs.com detection team.
Anyone in my network got an intro?

28.09.2025 01:14 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
YouTube Share your videos with friends, family, and the world

I gave a talk at the FIRST CTI conference in Berlin earlier this year. Here's my presentation in its entirety.
www.youtube.com/live/j23OubE...

20.09.2025 20:31 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image
16.09.2025 23:38 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thanks mate! Great post pulling the thread.

16.09.2025 19:27 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image
28.08.2025 21:45 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Tenable Cloud Security (CNAPP) Reduce cloud risk and exposure from faulty configurations and entitlements with our cloud-native application protection platform (CNAPP), Tenable Cloud Security.

Impressed withย the Tenable One CSPM demo at the #Tenable #BlackHat booth. Blends vulnerability scanning with cloud security + ASPM features via IaC scanning and Git integrations. Worth checking if you're comparing cloud security solutions:ย bit.ly/4mbhg3eย #BlackHat2025 #CloudSec

14.08.2025 22:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

See me at 11 am today on the #DEFCON Creator State 4 (room 228). I'm super excited for this, and a big "thank you!" to the #AdversaryVillage team!
#hackersummercamp @github.com

09.08.2025 16:07 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Yeah mate, iโ€™ll be there all week.

01.08.2025 20:01 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Threat actor uses AI to create a better crypto wallet drainer Safetyโ€™s malicious package detection identified a malicious package that appears to have been written by Claude AI

AI has written its first malicious package! I found an NPM package named @kodane/patch-manager that deploys a well-written persistent JavaScript crypto drainer.
Here's the thing: I'm pretty sure Claude wrote it!
Check out my post: getsafety.com/blog-posts/t...

@anthropic.com @npmjs.bsky.social

31.07.2025 20:50 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

The apocalypse is upon us!

17.07.2025 21:19 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0