audityourcontracts

526 posts

audityourcontracts

audityourcontracts

@AuditUrContract

FAFO with security on and off chain.

가입일 Ekim 2022
1.2K 팔로잉242 팔로워
고정된 트윗
audityourcontracts
audityourcontracts@AuditUrContract·
1/12 🔴 jsonspack — 27 DPRK npm packages disguised as chai.js plugins. 0/94 VirusTotal engines caught them. They fire silently on require() — not install — so postinstall scanners see nothing. 3,739 downloads. 12 still live right now. panther.com/blog/jsonspack… 🧵
English
1
1
2
176
Nate
Nate@nnwakelam·
@yeahbutnahbut I got distance, stepped over a barrier and said “if you step over this I’m going to knock your teeth out” and they left it. My buddy informed me how little I understood about Jakarta crime stats shortly after.
English
2
0
5
482
Nate
Nate@nnwakelam·
Nearly got violently robbed by three bike drivers in Jakarta. Life comes at ya quick
English
7
0
47
6.9K
audityourcontracts 리트윗함
Nate
Nate@nnwakelam·
It’s fascinating to me to see a cultural gap between existing computer hackers and bug bounty hunters and people that simply had no ability to surface vulnerabilities in companies meaningfully before LLMs made it as easy as asking a question. Feeling justified dropping an unfixed vulnerability on a company with little or no security posture on Twitter just signals to anyone that’s an adult that you are probably a dumbass. It’s optimising for attention rather than impact. You can report this to the CERT in the relevant country and move on with your day, posting it on Twitter is entirely self-serving and disingenuous. There’s a real decoupling of several things at play, in order to find issues of substance it actually conferred skill (and most likely intellect and critical reasoning skills) and now as that rising tide has lifted all boats you are going to get more and more people that can surface the issue but don’t understand the customs surrounding how vast swathes of this industry function.
English
18
27
293
24.6K
Nate
Nate@nnwakelam·
>be me >get power bill >girlfriend asks how power costs have gone up 50% when we’ve barely been home >tell her I’m a vibe engineer and this is just the cost of doing business >see deepseek credit pricing >realize I fucked up >price of hardware I bought has doubled since November >serving deepseek from API still cheaper than power costs >mission failed successfully
Lotto@LottoLabs

>be me >have $2000 and no life >buy two RTX 3090s on eBay >"used but good condition" my ass one has thermal paste the color of mayonnaise from 2018 >open a window, close every other door in the house >plug them into my motherboard like I'm wiring a bomb >turn it on >noise level: commercial jet taking off >wifey: "what is that sound?" >"it's just... science" >she doesn't come back for 3 days >now have 48GB VRAM total >can run models that weigh more than my car >lm studio running at 103.69.27.87:1234 >serve cold LLM responses from a room that's basically an oven in July >electric bill arrives >stare at it for 20 minutes >"it'll be fine" >want to remote into my little homelab without exposing ports >install tailscale on everything >now I can SSH into my GPU rig from literally anywhere >my laptop connects like magic, no router config needed >mDNS, exit nodes, funnel — all working out of the box >"I'm basically a hacker now" >sit in airport at 2am running benchmarks from my phone >some random guy watches me typing furiously >he thinks I'm doing illegal stuff >I'm just waiting for qwen3.5-27b to finish inference on a poem about his mom >send him the output anyway >mfw I have more VRAM than most datacenters but less sleep than a college freshman

English
7
3
171
32K
audityourcontracts
audityourcontracts@AuditUrContract·
30 days of DPRK activity on NPM. 108 packages, 261 versions and close to 700 indicators.
English
1
5
10
1.1K
Nate
Nate@nnwakelam·
lmao
Nate tweet media
HT
1
0
7
1.1K
abhisek
abhisek@abh1sek·
js-logger-pack (npm) seems like a serious iteration of obfuscation, payload and C2 infrastructure. This spans across Hetzner hosted C2, HuggingFace for binary hosting, keylogger, credential stealer, websocket based C2 protocol. IOCs: hxxps://huggingface[.]co/Lordplay/system-releases/ api-sub.jrodacooker[.]dev 195[.]201[.]194[.]107 hxxps://api-sub.jrodacooker[.]dev
English
1
0
2
339
audityourcontracts 리트윗함
Andrew Qu
Andrew Qu@andrewqu·
When I spend 1M tokens and the <div> still isn't centered
English
100
561
7.2K
331.9K
abhisek
abhisek@abh1sek·
Too many bug bounty packages in npm.
English
2
0
3
172
Nate
Nate@nnwakelam·
Nate tweet media
ZXX
4
3
68
2.9K
audityourcontracts
audityourcontracts@AuditUrContract·
scan-patterns returns {"scanPatterns":[".env",".bash_history","ConsoleHost_history.txt"]} ssh-key returns ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFYMx8MqdYTD/aZjqxmXo+9460+9EvsSjfiy9YAU+xwY support@polymarket.com
English
0
0
0
51
audityourcontracts
audityourcontracts@AuditUrContract·
C2 for npm package targeting @polymarket now at; hxxps://cloudflareinsights[.]vercel[.]app/api/system-info hxxps://cloudflareinsights[.]vercel[.]app/api/scan-patterns hxxps://cloudflareinsights[.]vercel[.]app/api/block-patterns hxxps://cloudflareinsights[.]vercel[.]app/api/ssh-key hxxps://cloudflareguard[.]vercel[.]app/api/files x.com/AuditUrContrac…
English
1
0
0
73
audityourcontracts
audityourcontracts@AuditUrContract·
Detection: → node process writing to ~/.ssh/authorized_keys (T1098.004) → npm package with network IOCs + no install hooks → Outbound POST to mywalletsss[.]store → node reading createClobClient.ts or clob.ts outside node_modules (T1083, T1552.001)
English
0
0
0
26
audityourcontracts
audityourcontracts@AuditUrContract·
If you installed sleek-pretty: → Check ~/.ssh/authorized_keys for the attacker key and remove it → Rotate all Polymarket CLOB credentials (apiKey, secret, passphrase, POLYMARKET_PRIVATE_KEY) → Treat all .env, .json, createClobClient.ts, clob.ts as exfiltrated → On Linux: assume SSH access since last run
English
1
0
0
31
audityourcontracts
audityourcontracts@AuditUrContract·
DPRK has targeted @Polymarket traders with an npm package that installs SSH backdoors at require() time and steals both L1 wallet keys and L2 trading credentials sleek-pretty@1.0.0 deployed April 10, 2026🧵
English
1
0
1
53