Ilkka Turunen's Avatar

Ilkka Turunen

@ilkka.turunen.dev

Field CTO @Sonatype, software supply chain and dependency management geek. Weekend hacker and synth butcherer ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ซ๐Ÿ‡ฎ

72
Followers
199
Following
21
Posts
24.07.2023
Joined
Posts Following

Latest posts by Ilkka Turunen @ilkka.turunen.dev

Preview
Fake npm 2FA reset email led to compromise of popular code packages - Help Net Security Malicious versions of 18 widely used npm packages were uploaded to the npm Registry following the compromise of their maintainer's account.

Fake npm 2FA reset email led to compromise of popular code packages

๐Ÿ“– Read more: www.helpnetsecurity.com/2025/09/09/n...

#cybersecurity #cybersecuritynews #accounthijacking @aikidosecurity.bsky.social @ilkka.turunen.dev @gossithedog.cyberplace.social.ap.brid.gy

09.09.2025 13:15 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Our malware systems at Sonatype seem to be picking these up coming from other, not yet reported accounts. This attack seems to have landed more publishers as this unfolds. Check your accounts folks while we work with others to contain.

08.09.2025 20:12 ๐Ÿ‘ 9 ๐Ÿ” 4 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1

Yep, I've been pwned. 2FA reset email, looked very legitimate.

Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again.

Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.

08.09.2025 15:15 ๐Ÿ‘ 187 ๐Ÿ” 59 ๐Ÿ’ฌ 15 ๐Ÿ“Œ 21
Preview
Releases ยท solana-labs/solana-web3.js Solana JavaScript SDK. Contribute to solana-labs/solana-web3.js development by creating an account on GitHub.

The web3.js compromise is a good example of legitimate library poisoning attacks. Sounds like a maintainer account was phished or an access token compromised. Basically any developer machine that installed this should be considered compromised github.com/solana-labs/...

05.12.2024 12:37 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I prefer to think of it more as extra predictive writing

27.11.2024 22:52 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

One synth to rule them all, one groove to find them,
One sound to bring them all, and in the rhythm bind them.

In the land of Roland, where the beats reside,
The 808 booms and the Juno glides.

27.11.2024 22:50 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Lord of the Rolands

27.11.2024 22:47 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

These are going to be big changes in the way we all do our work

20.11.2024 10:46 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Regulation - 2024/2847 - EN - EUR-LexLog inEnglish

The Cyber Resilience Act (aka CRA, aka Regulation (EU) 2024/2847) has been published in the Official Journal of the European Union eur-lex.europa.eu/legal-conten...

20.11.2024 10:29 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

That was a pretty stopping finding for us too. OSS as all software have increasingly deep dependency chains, there are move CVEs discovered by the day, leading to significant slowdowns. The NVD backlog is still increasing so expect this to keep going up

18.11.2024 12:00 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
The Onion Buys Alex Jonesโ€™s Infowars Out of Bankruptcy The satirical news site planned to turn Infowars into a parody of itself, mocking โ€œweird internet personalitiesโ€ who peddle conspiracy theories and health supplements.

Hi everyone.

The Onion, with the help of the Sandy Hook families, has purchased InfoWars.

We are planning on making it a very funny, very stupid website.

We have retained the services of some Onion and Clickhole Hall of Famers to pull this off.

I can't wait to show you what we have cooked up.

14.11.2024 14:09 ๐Ÿ‘ 58938 ๐Ÿ” 16010 ๐Ÿ’ฌ 2340 ๐Ÿ“Œ 4623

@axsharma.bsky.social wrote about it www.sonatype.com/blog/lottie-...

31.10.2024 09:56 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Malicious code in Lottie-Player CDN files ยท Issue #254 ยท LottieFiles/lottie-player after i use https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js or https://cdn.jsdelivr.net/npm/@lottiefiles/lottie-player@2.0.5/dist/lottie-player.min.js This popup opens on ...

So, lottie-player, a popular js dep for playing videos was taken over through compromised dev tokens github.com/LottieFiles/...

31.10.2024 08:50 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

Opetus kolmannella kielellรค tuottanee lรคhinnรค internationalishiรค joka ei kuulosta jรคrkevรคlle kenellekkรครคn. Uskon ettรค maahanmuutto- ja tyรถllistymisjรคrjestelmรค on se ongelma enemmรคn kuin suomenkieli, englanninkielinen lukiokoulutus ei kyllรค meikรคlรคisen paluumuuttoaikeita lisรคisi juurikaan

25.10.2024 13:20 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
SEC.gov | SEC Charges Four Companies With Misleading Cyber Disclosures Lock

Iโ€™m going to continue as i do on the other socials, posting whatโ€™s interesting to me. In this case that the SEC is going after companies that minimise cyber incidents, at least in the publicly traded realm. Not a huge hit to any one of them tho www.sec.gov/newsroom/pre...

25.10.2024 09:34 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

This is because any active oss project typically really cares about the issues. Whatโ€™s more alarming itโ€™s really consumption behaviours that are leading to risk. OSS is probably the most secure code you can get but the risk comes from forgetting itโ€™s there

24.10.2024 16:14 ๐Ÿ‘ 5 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

As one of the authors of the report that is cited in the article - the vulnerability count is a yard stick of popularity of open source. Last year we reported that OSS projects are actually WAY better at applying & producing security patches vs closed source and industry

24.10.2024 16:10 ๐Ÿ‘ 25 ๐Ÿ” 9 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 1

Very true. Fairly instant for me. And I donโ€™t have to look at the rubbish on the FYP

24.10.2024 15:54 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I do have to admit the air is so much cleaner here compared to the toxic smog over at Xitter. So nice to see actual tech twitter again

24.10.2024 15:47 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Preview
homer simpson from the simpsons is standing in front of a grassy field . ALT: homer simpson from the simpsons is standing in front of a grassy field .
24.10.2024 15:35 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Shhhh! I was enjoying lurking

24.10.2024 15:32 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I haven't been this excited about social media since 2011.

24.10.2024 03:48 ๐Ÿ‘ 691 ๐Ÿ” 35 ๐Ÿ’ฌ 19 ๐Ÿ“Œ 3

There is a new 'Rapid Reset' Vulnerability described by Cloudflare this week that affects the HTTP2 protocol. This implementation of HTTP2 is pretty widespread in different OSS libraries and embedded servers. Great writeup here blog.sonatype.com/10-open-sour...

12.10.2023 15:16 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Itโ€™s clear that what we have is both a gold rush and a productivity tool. You can see the adoption rate is enormous and the tech still finding its tracks

03.10.2023 17:20 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Huge news to share - weโ€™re live with our 9th State of the Software Supply Chain report. 1 in 8 downloads contain some documented risk - and most of that could easily be avoided! Read the whole package here ๐Ÿ‘‰ bit.ly/3LMRXo6

03.10.2023 13:48 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 1

The report goes into detail abt what are good indicators for security in a project - the top ones being code review process and no binaries committed. Weโ€™ll be publishing some updated findings next week. Imo also certain standard build artefacts like READMES, license and SBOM files are a must have

01.10.2023 11:40 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Hello world. Is this the federated social media to rule them all then?

25.07.2023 18:28 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0