Announcing my rejected talk for @bsidespyongyang:
Is that "web3 enthusiast" follower with the anime PFP acting suspicious?
Find out if you have confirmed North Korean followers at https://t.co/sR2776PBF2.
Link to my query: https://t.co/dqsNXAmeWs
Feel free to fork or adapt for other chains. This works in the free tier as long as you reasonably bound the date search window.
Scam alert🚨
A fake account of one of @EthPrague organizers reached out to me and asked to join a workspace
Some people I know also got targeted from other fake accounts
Be extremely careful and never copy and run scripts that you don't know, even if they're from "Google".
lmaooooooooooooooooo "we're not a casino" doesn't make up for your atrocious post-mortems
(regarding summer 2021 exploit #2...or maybe #3. this one 0x3a196410a0f5facd08fd7880a4b8551cd085c031)
I get a lot of mileage out of searching for just a bit larger Levenshtein distance for similar packages. Not really practical for an enterprise deployments but you get a lot of good candidates > 2-3 chars.
pulse-axios - malware on NPM
Eval.js has an unobfuscated loaded.
@sonatype@SocketSecurity There should be no less than a dozen yara rules firing on this. Looks like regular https://t.co/GWcKqTbg2Q patterns. Huge entropy. Node OS shelling.
NPM Malware Alert - https://t.co/BJ5bO6Bwb4
All versions drop a Windows stealer. Still live on NPM right now. Your pnpm cooldown scripts might not stop this - first commit was a month ago.
IOCs:
- emphasis-friday-even-administrator<.>https://t.co/CeVevaBKf7