Heya @steipete.me can you do something about malicious skills in your ClawHub registry? Last night, one user published 200 malicious skills. I am tracking a dozen threat actors all publishing multiple malicious skills into this registry, and I've emailed you about all of them, but got crickets back
01.02.2026 21:14
๐ 0
๐ 1
๐ฌ 0
๐ 1
Some of the most popular packages on the OpenClaw official registry ClawHub are malicious
@openclaw-x.bsky.social
01.02.2026 12:19
๐ 1
๐ 1
๐ฌ 0
๐ 0
Touche.
06.01.2026 22:39
๐ 1
๐ 0
๐ฌ 0
๐ 0
Ooooohh, this looks legit!
19.12.2025 06:06
๐ 1
๐ 0
๐ฌ 0
๐ 0
Another day, and another @hacker0x01.bsky.social "researcher" ganking people's AWS keys in a public NPM package (plugin-senna). ๐คฆโโ๏ธ
17.12.2025 06:18
๐ 0
๐ 0
๐ฌ 0
๐ 0
Bug bounty peeps, yo
15.12.2025 05:09
๐ 1
๐ 0
๐ฌ 0
๐ 0
As an Australian, my heart hurts today.
15.12.2025 02:23
๐ 0
๐ 0
๐ฌ 0
๐ 0
Promotion for Absolute AppSec episode with Paul McCarty, taking place today Dec 2 at 12 Noon Eastern time. The show livestream link is provided here: https://www.youtube.com/watch?v=UM4Fq6Q_Qpg
We have a special episode of @absoluteappsec.bsky.social today with Paul McCarty @6mile.githax.com who will help us make sense of the last few weeks of npm news. So join Paul @sethlaw.bsky.social and @cktricky.bsky.social at 12 Noon ET here: www.youtube.com/watch?v=UM4F...
02.12.2025 15:02
๐ 1
๐ 2
๐ฌ 0
๐ 0
We knew it was coming, and now it's here: Dynamic payloads have been found in @npmjs.bsky.social packages.
Ouch. ๐ฆ
18.11.2025 23:58
๐ 1
๐ 1
๐ฌ 0
๐ 0
Noice! I think this is the first time my work has been covered by @bleepingcomputer.com
14.11.2025 21:19
๐ 0
๐ 0
๐ฌ 0
๐ 0
I'm on @thehackernews.bsky.social again
13.11.2025 19:31
๐ 1
๐ 0
๐ฌ 1
๐ 0
I've identified a new worm affecting NPM. I'm calling it "IndonesianFoods" based on its internal dictionary. The intent is to generate assets on the Tea Protocol blockchain.
It's dumb, but it's MASSIVE!
Check the link ๐
sourcecodered.com/indonesianfo...
@npmjs.bsky.social @github.com
12.11.2025 23:30
๐ 0
๐ 1
๐ฌ 0
๐ 0
I suspect a lot of full time BB peeps are doing the same
05.11.2025 13:28
๐ 0
๐ 0
๐ฌ 0
๐ 0
I like the one-two combo you got going there picklerick
23.10.2025 00:06
๐ 1
๐ 0
๐ฌ 1
๐ 0
Don't let AI write your payloads for you if you don't know what you're doing. Otherwise, you might end up publishing your API keys, environment variables, and identity to @npmjs.bsky.social
16.10.2025 22:41
๐ 0
๐ 1
๐ฌ 0
๐ 0
Want to sniff out private bug bounty programs? If you monitor OSV for new malicious packages, you'll get some great intel. Today's example: @npmjs.bsky.social user Paastha published 6 packages targeting @vercel.com. But wait, they don't have a BB program?! Or do they.... ๐ฎ๐ฅ
08.10.2025 21:24
๐ 1
๐ 0
๐ฌ 0
๐ 0
Tell me that @v0.dev has a bug bounty program without telling me they have a bug bounty program.
#dependencyconfusion #maliciouspackage
08.10.2025 08:38
๐ 1
๐ 1
๐ฌ 0
๐ 0
Heya homie, that ain't gonna work.
07.10.2025 09:31
๐ 0
๐ 0
๐ฌ 0
๐ 0
Yes, thanks for follow up
30.09.2025 18:41
๐ 1
๐ 0
๐ฌ 0
๐ 0
I need to talk to someone in the @reversinglabs.com detection team.
Anyone in my network got an intro?
28.09.2025 01:14
๐ 1
๐ 1
๐ฌ 2
๐ 0
YouTube
Share your videos with friends, family, and the world
I gave a talk at the FIRST CTI conference in Berlin earlier this year. Here's my presentation in its entirety.
www.youtube.com/live/j23OubE...
20.09.2025 20:31
๐ 0
๐ 0
๐ฌ 0
๐ 0
16.09.2025 23:38
๐ 2
๐ 1
๐ฌ 0
๐ 0
Thanks mate! Great post pulling the thread.
16.09.2025 19:27
๐ 1
๐ 0
๐ฌ 0
๐ 0
28.08.2025 21:45
๐ 0
๐ 0
๐ฌ 0
๐ 0
Tenable Cloud Security (CNAPP)
Reduce cloud risk and exposure from faulty configurations and entitlements with our cloud-native application protection platform (CNAPP), Tenable Cloud Security.
Impressed withย the Tenable One CSPM demo at the #Tenable #BlackHat booth. Blends vulnerability scanning with cloud security + ASPM features via IaC scanning and Git integrations. Worth checking if you're comparing cloud security solutions:ย bit.ly/4mbhg3eย #BlackHat2025 #CloudSec
14.08.2025 22:30
๐ 1
๐ 0
๐ฌ 0
๐ 0
See me at 11 am today on the #DEFCON Creator State 4 (room 228). I'm super excited for this, and a big "thank you!" to the #AdversaryVillage team!
#hackersummercamp @github.com
09.08.2025 16:07
๐ 1
๐ 0
๐ฌ 0
๐ 0
Yeah mate, iโll be there all week.
01.08.2025 20:01
๐ 1
๐ 0
๐ฌ 0
๐ 0
Threat actor uses AI to create a better crypto wallet drainer
Safetyโs malicious package detection identified a malicious package that appears to have been written by Claude AI
AI has written its first malicious package! I found an NPM package named @kodane/patch-manager that deploys a well-written persistent JavaScript crypto drainer.
Here's the thing: I'm pretty sure Claude wrote it!
Check out my post: getsafety.com/blog-posts/t...
@anthropic.com @npmjs.bsky.social
31.07.2025 20:50
๐ 1
๐ 0
๐ฌ 1
๐ 0
The apocalypse is upon us!
17.07.2025 21:19
๐ 0
๐ 0
๐ฌ 0
๐ 0