Trust Wallet's Chrome extension was compromised on Christmas Eve. $7M drained.
We dug into the code. The attack was worse than reported - it triggered on every unlock, not just seed phrase imports.
Full technical breakdown:
https://t.co/Tcak5IJKms
#TrustWallet
๐จ ๐ช๐ฒ'๐๐ฒ ๐๐ป๐ฐ๐ผ๐๐ฒ๐ฟ๐ฒ๐ฑ ๐๐ต๐ฒ ๐ณ๐ถ๐ฟ๐๐ ๐บ๐ฎ๐น๐ถ๐ฐ๐ถ๐ผ๐๐ ๐ ๐๐ฃ ๐๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ถ๐ป ๐๐ต๐ฒ ๐๐ถ๐น๐ฑ.
It was only a matter of time. The postmark-mcp npm package (1,500+ weekly downloads) has been backdoored since v1.0.16 - silently BCCing every email to the attacker's server.
The developer built trust through 15 legitimate versions, then added one line of code that compromised everyone. When confronted, they deleted the package to cover tracks, but existing installations are still actively leaking emails.
If you're using postmark-mcp, uninstall it NOW.
This is what happens when we give anonymous developers god-mode access to our AI assistants with zero security controls.
๐จ Using Axiom for trading? A new Firefox extension is targeting you.
It claims "100% local execution"
Reality? It steals your credentials + wallet info, sends them to a remote server, and hides behind obfuscation and anti-detection.
Always verify in Koidex
ID: axiomtool
๐จ Edge users beware!
The โVideo Downloaderโ extension (video-downloader) is stealing all your cookies and sending them to an external server.
This isnโt a downloader - itโs a data exfiltration tool.
Extension ID: agkcnnlfkebmgmohngapnkfihefhkoia
๏ฟฝ๏ฟฝ๏ฟฝ๏ฟฝ Marketplace Takeover: Millions at Risk ๐จ
Today, weโre lifting the embargo on one of the most critical supply-chain vulnerabilities weโve ever seen.
Our team at Koi Security discovered a flaw in Open-VSX - the open extension marketplace used by over 8 million developers across VSCode forks like @cursor_ai , @windsurf_ai , Firebase Studio, and many more.
Through a misconfigured CI workflow, a malicious actor could silently overwrite every extension in the marketplace. Full control over millions of dev machines.
This was a SolarWinds-class risk for developer tooling.
We responsibly disclosed the bug in May, worked closely with the Eclipse Foundation on the fix, and today weโre sharing the full write-up โ because the ecosystem deserves transparency and protection.
Imagine being an American post 9/11, but instead of mourning your people you are busy convincing the world that the twin towers actually existed, that airplains literally crashed into them, that actual people were jumping down. This is how I feel wandering around here these days
His name is Tarek Abu-Arar, an Arab Muslim Israeli doctor. On a Saturday morning, he was driving to his hospital shift when he suddenly came across a person lying by the roadside. When he got out of the car and approached to help, that person shot Tarek. He was a Hamas terrorist.
Suddenly, ten more terrorists emerged from the bushes, taking him at gunpoint as a hostage while continuing to shoot at passing cars and kill civilians. When the military forces arrived, the fucking terrorists used Tarek as their human shield, all while he bled profusely and prayed in Arabic for mercy. Throughout this nightmare, the terrorists knew Tarek was an Arab, they knew he was a Muslim, and they simply didn't care.
Tarek was eventually rescued and remained alive by a miracle, but many Arab-Israeli lives have been taken by Hamas on that tragic day. To Hamas, it doesn't matter if you're Muslim or Jewish; their only faith is in murder. Please share #HamasisISIS
Heartbroken by the horrific terrorist attacks on Israel and the escalating conflict. My deepest condolences are with all those killed and impacted. Our focus remains on ensuring the safety of our employees and their families. Below is a message we shared with Microsoft employees today about our response. https://t.co/FFi0Z7yt2K
Imagine the worst things possible that can be done to humans.
Hamas did all of that and more to Israeli civilians. Babies beheaded. People burned alive in their homes. Women raped and dragged through the streets.
Donโt look away.
I'm excited about this one ๐ Hunt in Microsoft 365 Defender without KQL! Our new query builder is now in public preview
https://t.co/9kUFUpYmiy thanks @Taliash1
#AdvancedHunting AADSignInEventsBeta table now includes EndpointCall field which indicates Azure AD endpoint involved in the request (including MFA requests: SAS:BeginAuth, SAS:ProcessAuth, SAS:EndAuth EndpointCalls). Happy hunting! #M365D