Live data from Hacker News

Viewing profile — varunsharma07

varunsharma07

HN member
Joined
Sat, Jul 03, 2021, 1:00 PM UTC
HN karma
683
Public activity
129 items

About varunsharma07

Founder of StepSecurity (https://www.stepsecurity.io)

Recent public activity

  1. comment
    Comment #49171909

    We (StepSecurity) published a full analysis of both payload stages: https://www.stepsecurity.io/blog/chaindrop-npm-worm Some additional detail from our analysis: 1. Provenance did …

  2. story
  3. story
  4. comment
    Comment #48564926

    Mastra is an open-source TypeScript framework for building AI agents, workflows, and RAG pipelines. The StepSecurity Threat Intelligence Team has identified that multiple mastra np…

  5. story
  6. story
  7. comment
    Comment #48243490

    On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote every git tag across multiple popular Composer packages within a single 15 minute wind…

  8. story
  9. story
  10. story
  11. comment
  12. story
  13. comment
    Comment #48110796

    We have built an AI Package Analyst https://app.stepsecurity.io/oss-security-feed and also monitor them using https://github.com/step-security/harden-runner for runtime behavior.

  14. comment
    Comment #48101988

    @mistralai/mistralai npm package was also compromised as part of this worm https://github.com/mistralai/client-ts/issues/217 It has been pulled from the npm registry now.

  15. comment
    Comment #48100707

    The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed firs…

  16. story
    Postmortem: TanStack NPM supply-chain compromise

    https://github.com/TanStack/router/issues/7383

  17. comment
    Comment #47392215

    The StepSecurity threat intelligence team discovered that dev-protocol — a verified GitHub organization with 568 followers belonging to a legitimate Japanese DeFi project — has bee…

  18. story
  19. comment
    Comment #47378424

    An attacker is compromising hundreds of GitHub accounts and injecting identical malware into hundreds of Python repositories. The earliest injections date to March 8, 2026, and the…

  20. story
  21. story
  22. story
  23. comment
    Comment #47205262

    The root cause is workflows that grant trust to untrusted inputs: pull_request_target that checks out and executes fork code with repo secrets, ${{ }} expressions that interpolate …

  24. comment
    Comment #47205102

    We analyzed an autonomous bot (hackerbot-claw) that's actively scanning GitHub repos for exploitable Actions workflows. It hit Microsoft, DataDog, a CNCF project, and awesome-go (1…

  25. story