super excited to be hosting over 12 events with some incredible companies for new york tech week at @vercinyc
our space will be transforming into a free cafe for the week, host some amazing speakers, turn into a jazz speakeasy for the night, bring together creatives, and so much more...
link in comments with all events
if you’re in NYC for the week, comment below or shoot me a message!
@github lmaoooooooo people have been literally BEGGING to help microsoft get their arms around the EASILY DETECTABLE shit in vscode for YEARS now
rip motherfuckers
just enabled a minimum age on npm package installs for my machine, should've done this sooner but if you haven't either here's a prompt for your coding agent to configure it for you:
""Find my package manager (bun/pnpm/npm/yarn) and configure a 3-day minimum-release-age / cooldown for installs to blunt supply-chain attacks. Exempt my workspace scopes. Verify the exact config key in current docs before writing."
Ghostty is leaving GitHub. I'm GitHub user 1299, joined Feb 2008. I've visited GitHub almost every single day for over 18 years. It's never been a question for me where I'd put my projects: always GitHub. I'm super sad to say this, but its time to go. https://t.co/DQDemHdytV
Hey @AnthropicAI let's go toe to toe
I bet $100,000 my agent finds more valid Critical/High/Medium total smart contract vulns than Mythos, 1 run each
I'm a small boii here in web3 security, your "scary" agent wouldn't be afraid of mine, no? Serious bet. Tag anyone, I'm ready.
Done switching tabs between ESPN, your sportsbook, Polymarket & Kalshi every big play?
Stratos Sports: live scores, betting lines & real-time Polymarket + Kalshi on ONE screen.
Prototype live: https://t.co/gAdkBlCvAY
No signup. Try it & tell us what to build next 👀
it's a remarkable milestone for anyone working on compilers and smart contract security: Vyper is set to become the _first_ formally verified smart contract compiler, effectively allowing you to mathematically prove that the entire compilation pipeline preserves the contract logic _and_ to prove that the contract logic itself is correct. Oh, and the cool thing is, my snekmate math functions have been formally verified :D. 🐍💙
Kalshi wants to get more young women interested in the prediction-market platform, looking to expand beyond sports and its core male customer base. https://t.co/DEMZaRstUj
The quoted post is actually a cool live Contagious Interview DPRK 🇰🇵Gitlab repo that deserves more attention and more context! Malware for MacOS, Windows and Linux
🧵IOCs in post
#1 - Delivery
ref: https://t.co/xTATnjGYGh
Created Jan 21th, posing as a fake "Real Estate Rental Platform"
link: /gitlab.com/real-estate-review3/real-estate-demo
Full repo backup here: a9edb291d912638f9652b2c8c982b7c6b289b0434fb467e0a515dccec68653e0
User - [email protected]
We can easily spot the malicious curl requests depending on the OS, prepared to run on MacOS, Windows and Linux.
Payloads hosted in vscode-load[.]onrender[.]com, to see them while they are live please use a Curl User-Agent, any way I saved them all
#2 - Windows #OtterCookie
Detonation here: https://t.co/qHLTSOK7dY
On Windows, a script hosted on vscode-load[.]onrender[.]com/settings/windows?flag=9 creates file "vscode-bootstrap.cmd" - c40ccf9bed5ceaab36d59e529f17a9b424c037649026db0ffe963c23fd586d19
Content hosted on vscode-load[.]onrender[.]com/settings/bootstrap?flag=9 -
c226eb59cf696a85ed7134b57f12d82cb392d42b908dd6a463cd4d8c980ee5e8
This second script installs NodeJS via powershell and uses it to install dependencies (axios) used to run the malware, hosted on vscode-load[.]onrender[.]com/settings/package - b12a4325fe5af59d64ca617df254841d16f1e5250acd24be518971bce93637ff
and also fetch https://vscode-load[.]onrender[.]com/settings/env?flag=9 - 40990ab0b482a780456e75609ebee3b883f912d75811f9f0dfb022ccdd862f9f
that will fetch the malicious obfuscated JavaScript from ip-api-check-gold[.]vercel[.]app/icons/709 (you can fetch via curl with custom header "bearrtoken: logo")- dbdfe6e24e5c0fa78ae174877cdae7d49b24da529bda78af9a6468a2453f189b
This malicious JS connects the infected machine to the OtterCookie C2:
System info and credentials send to
hxxp://144.172.116.80:8085/upload
Computer files upload to
hxxp://144.172.116.80:8086/upload
API client comunication sent to
hxxp://144.172.116.80:8087/api/log
hxxp://144.172.116.80:8087/api/notify
Also a websocket pipeline is opened here hxxp://144.172.116.80:8087/socket.io/*
The build decodes data from browsers using Windows DPAPI for the current user and starts a loop to read clipboard content
#3 - MacOS & Linux @txhaflaire
For ref: https://t.co/6vXMOJmLm8
On MacOS, a bash script hosted on vscode-load[.]onrender[.]com/settings/mac?flag=9 - 6be45e165de60b61e9b7cb9e1f9b72c652c388a04c02d2068de6188cc88fc3fe
On Linux a bash script hosted on vscode-load[.]onrender[.]com/settings/linux?flag=9 -f03af0598d13d868580527299f5caad51b3d50cd3d655bd810aaaf90bef21f0a
Both creating a file "vscode-bootstrap sh", content hosted on vscode-load[.]onrender[.]com/settings/bootstraplinux?flag=9 - 60914b8df5b5d64070f71ef13817499b3a85de98433ae5c01bd235abec9464f6
The overall functionality is the same than on windows, loading and executing the same JS code.
Feel free to check!
> be a lazy dev
> let LLM analyse an Etherscan verified contract
> LLM has code execution capabilities
> LLM listens to the instructions part of the verified source code comments
> get rekt
The future is full of prompt injection attacks. Looking forward to 2026.
ps: this is an illustrative contract I wrote without fancy obfuscation, so pls don't get too much inspired ;)
Lastly, if they hack your telegram, you need to TELL EVERYONE ASAP.
"You" are about hack your friends.
Please put your pride aside and SCREAM abt it.
And if you need help with any of this SEAL-911 (@_SEAL_Org) is here for you.
Message us 24/7: https://t.co/GQX74s9Ohc
We will be hosting a roundtable on Dec. 16 to discuss Rule 611 of Regulation NMS and other associated rules and regulatory requirements. A livestream will be available on https://t.co/kacEcVjwPi.
See details on agenda, panelists, and registration info: https://t.co/TNcnpgobrY