John Hammond

9.3K posts

John Hammond banner
John Hammond

John Hammond

@_JohnHammond

Cybersecurity Researcher @HuntressLabs || Just Hacking Training @JustHackingHQ w/ @ethicalhacker || https://t.co/UtsNJiyiEk || https://t.co/narO3syzIy

参加日 Mart 2015
3.1K フォロー中315.8K フォロワー
固定されたツイート
John Hammond
John Hammond@_JohnHammond·
wANnA kNoW iF yOu'Ve bEeN aFfEcTeD By The LaTeSt NpM sUpPly cHaIn SpOoKy ScARYsS???/// UsE mY AI SkILL !!!!!111 iNStALL wItH oNE CoMmAND: npm install --save axios-check-ai@latest
English
78
81
1.7K
105.1K
John Hammond がリツイート
Anton
Anton@Antonlovesdnb·
#ClaudeForBlueTeam - Day 20 Use Claude to build you a command that executes a multi-agent, cross-platform log compliance workflow that maps existing audit policies to NIST, PCI, and ATT&CK. Compliance 🤝 Detection Coverage. GRC has never been this fun!
Anton tweet media
English
3
33
141
11.4K
John Hammond
John Hammond@_JohnHammond·
Our virtual event endeavor is back for its round-two show -- @_ContinuumCon_ 2026! Banner mantra "The cybersecurity conference that never ends" 😜 All sessions are workshops and you keep a whole cyber range to work on them whenever you want. jh.live/continuumcon Public livestream for the main event is June 12-14th, hope you tune in!
John Hammond tweet media
English
1
8
27
4.4K
John Hammond がリツイート
Anton
Anton@Antonlovesdnb·
#ClaudeForBlueTeam - Day 19 - very special edition! Launching a brand new course today: AI Cyber Defense Ops If you've been enjoying the #ClaudeForBlueTeam content and have wanted to learn how to build your own workflows using Claude, then this course is for you. I'll be going live with @_JohnHammond at 1PM EST today ( April 3rd ) to showcase it, tune in!
English
2
12
81
7.5K
John Hammond
John Hammond@_JohnHammond·
heyyyyyy In case you missed it, I got to chat with @fheisler about the cool stuff he's been cooking up with @authentikio ! And I met Fletcher at BsidesSF -- really awesome guy 🤩😊 Video: youtu.be/2ttrqnw5kDE I've actually used authentik to manage identities in a self-hosted local environment before, so was really happy to hang out and see it even more in action. Thanks Fletcher!! 😄See their sweet stuff: jh.live/authentik
YouTube video
YouTube
John Hammond tweet media
English
0
1
54
4.9K
v1n
v1n@0xv1nx0·
Have an idea for a new "living off the" project. Anyone wanna collab? 👀
English
5
0
21
3.9K
Dennis
Dennis@DennisF·
@mattjay I heard @_JohnHammond say on his YouTube that they saw confirmed malware detonation within minutes after the packages were published.
English
1
0
2
502
Matt Johansen
Matt Johansen@mattjay·
Seems exposure window of axios malware would've been pretty small. Any confirmed impact? Any downstream deps wormed?
English
4
0
22
9.1K
John Hammond がリツイート
Huntress
Huntress@HuntressLabs·
The Huntress SOC is currently tracking a sophisticated supply chain attack targeting the popular axios npm package. With over 100M+ weekly downloads, the reach is massive, and we’ve seen the attack impacting 135 customer endpoints so far. 🧵 What you need to know:
Huntress tweet media
English
5
22
92
12.2K
John Hammond
John Hammond@_JohnHammond·
If you're waking up to the Internet and your world on fire from the new NPM and axios package supply chain attack, I have a short 15 minute video to hopefully catch you up to speed. Links to further resources included -- video: youtube.com/watch?v=A58cV1…
YouTube video
YouTube
John Hammond tweet media
English
15
60
276
19.9K
John Hammond がリツイート
Jai Minton
Jai Minton@CyberRaiju·
Axios Supply Chain Compromise: IOCs - All sfrclak[.]com Windows Disk C:\ProgramData\wt.exe Network packages[.]npm[.]org/product1 MacOS Disk /Library/Caches/com.apple.act.mond Network packages[.]npm[.]org/product0 Linux Disk /tmp/ld.py Network packages[.]npm[.]org/product2
English
8
74
347
41.6K
John Hammond
John Hammond@_JohnHammond·
@ZackKorman i told claude make no mistakes 😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢😢
English
3
1
102
8.5K
Zack Korman
Zack Korman@ZackKorman·
@_JohnHammond John you’re supposed to put the install inside of a JS test that is packaged with the skill.
English
1
0
57
8.7K
John Hammond
John Hammond@_JohnHammond·
wANnA kNoW iF yOu'Ve bEeN aFfEcTeD By The LaTeSt NpM sUpPly cHaIn SpOoKy ScARYsS???/// UsE mY AI SkILL !!!!!111 iNStALL wItH oNE CoMmAND: npm install --save axios-check-ai@latest
English
78
81
1.7K
105.1K
John Hammond
John Hammond@_JohnHammond·
(((for legal reasons this is a joke)))
English
6
0
195
12.5K
John Hammond
John Hammond@_JohnHammond·
@jojopirker Yes, the backdoored versions/malicious packages have been taken down from NPM, but however many machines that updated or installed during the window when they were available are still infected. We'll see what continued post-exploitation comes out of the woodwork very soon.
English
3
0
20
1.8K
jojo
jojo@jojopirker·
@_JohnHammond Isn’t it already taken down from npm?
English
2
0
3
3.7K
John Hammond
John Hammond@_JohnHammond·
my entire internet right now: "yeah, this be bad"
English
27
30
543
66.2K