Viewing profile — varunsharma07
varunsharma07
HN member- Joined
- Sat, Jul 03, 2021, 1:00 PM UTC
- HN karma
- 683
- Public activity
- 129 items
- HN profile
- View on Hacker News ↗
About varunsharma07
Recent public activity
-
comment
Comment #49171909
We (StepSecurity) published a full analysis of both payload stages: https://www.stepsecurity.io/blog/chaindrop-npm-worm Some additional detail from our analysis: 1. Provenance did …
- story
- story
-
comment
Comment #48564926
Mastra is an open-source TypeScript framework for building AI agents, workflows, and RAG pipelines. The StepSecurity Threat Intelligence Team has identified that multiple mastra np…
- story
- story
-
comment
Comment #48243490
On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote every git tag across multiple popular Composer packages within a single 15 minute wind…
- story
- story
- story
-
comment
Comment #48137698
[dead]
- story
-
comment
Comment #48110796
We have built an AI Package Analyst https://app.stepsecurity.io/oss-security-feed and also monitor them using https://github.com/step-security/harden-runner for runtime behavior.
-
comment
Comment #48101988
@mistralai/mistralai npm package was also compromised as part of this worm https://github.com/mistralai/client-ts/issues/217 It has been pulled from the npm registry now.
-
comment
Comment #48100707
The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed firs…
-
story
Postmortem: TanStack NPM supply-chain compromise
https://github.com/TanStack/router/issues/7383
-
comment
Comment #47392215
The StepSecurity threat intelligence team discovered that dev-protocol — a verified GitHub organization with 568 followers belonging to a legitimate Japanese DeFi project — has bee…
- story
-
comment
Comment #47378424
An attacker is compromising hundreds of GitHub accounts and injecting identical malware into hundreds of Python repositories. The earliest injections date to March 8, 2026, and the…
- story
- story
- story
-
comment
Comment #47205262
The root cause is workflows that grant trust to untrusted inputs: pull_request_target that checks out and executes fork code with repo secrets, ${{ }} expressions that interpolate …
-
comment
Comment #47205102
We analyzed an autonomous bot (hackerbot-claw) that's actively scanning GitHub repos for exploitable Actions workflows. It hit Microsoft, DataDog, a CNCF project, and awesome-go (1…
- story