Max Vox
702.7K posts

Max Vox
@DukeZer0
Vibe Engineer - Habitual Line Respecter Anti-Authoritarian - Anti-Extremist Manic Pixie Dream Guerrilla - General Internet Goer formerly known as Duke Zero




Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.

@spilkommen @AethrMusik Hello Mr. Spilkommen. @RealBoon22 and myself are currently working on a collab project. We are trying to get a bunch of musicians and do a big collab song like they used to do back in the day on TV. It would be really cool if you'd join us as well. youtu.be/s3wNuru4U0I?si…

Features are now live on @AethrMusik Tag any artist on the platform when you upload or edit a track their name appears clickable next to yours everywhere your track shows up. Each name links to that artist's profile. Tagged artists get notified, see your track in a new "Featured on" section on their profile, and can remove themselves anytime. Off-platform collaborators get a free-text credit so nobody gets left out of the liner notes. Works on singles, EPs, and albums. Opens up a doorway for artists on AethrMusik to collab with each other <3





















