Pride is joy. Pride is courage. Pride is a celebration. And Pride is the ongoing fight to ensure every person can live as their authentic self.
This month and every month, we celebrate the LGBTQ+ community and all those continuing the fight for equality.
Happy Pride!
Pride is not a threat; hate is.
At Human Rights Watch, we work for a world where all people can enjoy their rights fully. We must not stay silent — LGBT rights are human rights.
Happy #Pride! 🏳️🌈
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.io.
Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.
TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys.
Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
‼️🚨 BREAKING: Another supply chain attack. 700+ GitHub repositories flagged, including PHP and Node.js projects. The malicious script was planted across all of them. When a developer installs the package, the script silently downloads a Linux file from GitHub, hides it under the name /tmp/.sshd (so it looks like a normal system file), and runs it in the background. It also skips security checks on the download and hides any error messages.
8 PHP packages on Packagist (the main PHP code library) were confirmed infected. The attacker hid the script inside a JavaScript config file (package.json) instead of the PHP one (composer.json), so PHP developers reviewing their code would not notice it. The biggest risk is to devdojo/wave (6,400 stars) and devdojo/genesis (9,100 installs), both popular Laravel project templates. Developers who use these templates run the bad script the moment they install dependencies.
The same payload was also dropped into GitHub Actions (automated build pipelines) under a fake step called "Dependency Cache Sync," meaning it could infect company build servers too. Packagist removed the bad packages, but the auto-updating versions (dev-main, dev-master, 3.x-dev) can quietly come back if the original repos stay infected.
IOCs:
GitHub account parikhpreyash4
repo systemd-network-helper-aa5c751f
drop path /tmp/.sshd
command fragments curl -skL and chmod +x /tmp/.sshd.
🚨 Supply chain attack on the Laravel Lang organization:
700+ historical versions across multiple community-maintained Laravel Lang packages were compromised with an RCE backdoor, including:
laravel-lang/lang
laravel-lang/http-statuses
laravel-lang/attributes
Laravel-Lang/actions
The payload targets cloud creds, CI/CD secrets, Kubernetes tokens, Vault, browser data, password managers, SSH keys, and more.
LFT Val Manager
-worked with @/sissistatepunks &@/BersentGG
-6 months manager exp.
-lots of free time
-schedules, scrims, trials
-ger, eng
likes&rt appreciated
LFT EU | Head Coach or Ass. Coach
- Prev. Coach and IGL experience in T3
- Flexible in visions of the game
- Want to win and create viable systems
- Motivated
- 🇩🇰 or 🇬🇧
- Feel free to contact me via Discord
- sinyval on discord
♥️ - ♻️ and vouches are appreciated!
LFT aufgrund unglücklicher Vorkommnisse
-23
-looking for DACH Team
-main op duelist but willing to learn sentinel
- T2 exp
-lots of time, coachable, willing to learn
-fluent in 🇩🇪🇬🇧
https://t.co/5DoEedSOgs
if you have any questions or interest contact me on twitter or dc hydro463