Live data from Hacker News

Viewing profile — 6mile

6mile

HN member
Joined
Wed, Dec 30, 2020, 11:59 AM UTC
HN karma
134
Public activity
53 items

About 6mile

Software supply chain research, created GitHax, threat intel platform for supply chain threats and former founder of SecureStack. Author of open-source projects like the DevSecOps Playbook, TVPO threat modelling framework, and more.

Recent public activity

  1. comment
    Comment #49154572

    DPRK has created a new leaner technique to obfuscate its C2 payloads with NullReceiver. The NPM packages call the Ethereum blockchain directly to find hidden addresses in the desti…

  2. story
  3. comment
    Comment #48837879

    Because the Go and Packagist registries don't require additional publishing credentials like NPM and PyPI North Korean threat actors have been able to compromise legitimate package…

  4. story
  5. comment
    Comment #48590683

    NPM attack targeting Mastro targets browser extensions other than crypto wallets. - Credential managers and MFA authenticators from LastPass, Bitwarden, 1Password, Deloitte, Dashla…

  6. story
  7. comment
    Comment #48418319

    Signs point to the Miasma worm, but this is unconfirmed yet.

  8. story
  9. comment
    Comment #48186769

    The same threat actor that compromised Axios published three additional NPM packages within 18 hours. Unfortunately, these packages are still alive on NPM and compromising victims.…

  10. story
  11. comment
    Comment #48028429

    If you are a Kubernetes shop, you will want to check whether you are using the Antrea project. Nothing malicious has been deployed yet, as we caught this one early, but the threat …

  12. story
  13. story
  14. story
  15. comment
    Comment #47875158

    TeamPCP claims another victim and this time they call it "Shai-Hulud: The Third Coming"

  16. story
  17. comment
    Comment #47829659

    We have helped several orgs with incident response and this is the playbook that we used.

  18. story
  19. comment
    Comment #47341573

    The bash script for checking for infection? is that what you are talking about?

  20. story
  21. story
  22. story
  23. comment
    Comment #46725548

    Hi, I'm one of the researchers that identified this threat and I blogged about it back in November ( https://opensourcemalware.com/blog/contagious-interview-vsco... ) First, @Tyria…

  24. comment
    Comment #46587685

    This malware is a full-featured RAT that uses Telegram for C2 and is only 143 lines of code. It's "RAT-as-a-library" design means that we are already seeing criminals build more co…

  25. story