P.E.M.B

50 posts

P.E.M.B banner
P.E.M.B

P.E.M.B

@0xPEMB

Reformed Christian | Security Researcher | 🗣️ English, Português "Bridging Adversary Analysis and Cyber Education — One TTP at a Time."

Houston, TX Katılım Mart 2020
119 Takip Edilen15 Takipçiler
John Hammond
John Hammond@_JohnHammond·
If you're waking up to the Internet and your world on fire from the new NPM and axios package supply chain attack, I have a short 15 minute video to hopefully catch you up to speed. Links to further resources included -- video: youtube.com/watch?v=A58cV1…
YouTube video
YouTube
John Hammond tweet media
English
11
56
223
14.7K
P.E.M.B
P.E.M.B@0xPEMB·
@_JohnHammond Am I the only one who saw that nx/ai-agents was also compromised?😂😂 I need intell corroboration
English
0
0
1
144
P.E.M.B retweetledi
Jai Minton
Jai Minton@CyberRaiju·
Axios Supply Chain Compromise: IOCs - All sfrclak[.]com Windows Disk C:\ProgramData\wt.exe Network packages[.]npm[.]org/product1 MacOS Disk /Library/Caches/com.apple.act.mond Network packages[.]npm[.]org/product0 Linux Disk /tmp/ld.py Network packages[.]npm[.]org/product2
English
3
59
299
34.5K
P.E.M.B
P.E.M.B@0xPEMB·
🚨CRITICAL: Active supply chain attack is not affecting axios only. @nx/ai-agents @nx/ai-agents/configure-ai-agents is also affected and pushing the same malicious van script through post install “setup.js”. The Malicius VBscript is being written in “C:\Users\%username%\AppData\Local\Temp\6202033.vbs” which then makes the post request to “hxxp://sfrclak[.]com”. Goodnight Defenders! #axios #nx #ai #critical #supplychain #cyberattack
English
0
0
1
87
Katie Paxton-Fear
Katie Paxton-Fear@InsiderPhD·
Every single npm supply chain attack 🤦‍♀️
Katie Paxton-Fear tweet media
English
2
1
50
1.7K
P.E.M.B
P.E.M.B@0xPEMB·
🚨CRITICAL: Active supply chain attack is not affecting axios only. @nx/ai-agents @nx/ai-agents/configure-ai-agents is also affected and pushing the same malicious van script through post install “setup.js”. The Malicius VBscript is being written in “C:\Users\%username%\AppData\Local\Temp\6202033.vbs” which then makes the post request to “hxxp://sfrclak[.]com”. Goodnight Defenders! #axios #nx #ai #critical #supplychain #cyberattack
English
0
0
0
44
P.E.M.B
P.E.M.B@0xPEMB·
About 3 days ago I wrote an article on #SLHS’s recent vishing campaign abusing trust in SSO domains and doing brand #impersonation with subdomains. The apex domain (passkeysso[.]com) was being flagged heavily on @virustotal but today it’s cleared out. Who knows how this is updated? #explain My blog post is here: pemblabs.net/Hiding-in-Plai…
P.E.M.B tweet mediaP.E.M.B tweet media
English
0
0
0
7
P.E.M.B
P.E.M.B@0xPEMB·
@cyb3rops Hard to distinguish whether this is an update or a new compromise. Do you have a timeline?
English
1
0
2
3K
P.E.M.B
P.E.M.B@0xPEMB·
I’m curious! Did anyone ever got paid for this? If you send AI voice, will they still clone it? #ai #voice #clone
P.E.M.B tweet media
English
0
0
0
17
The Dallas Express News
The Dallas Express News@DallasExpress·
DALLAS H-1B VISA FRAUD BUST: Federal prosecutors charge two men with running a 7-year scheme submitting fake H-1B and green card applications through a local law office. Defendants Abdul Hadi Murshid and Muhammad Salman Nasir face conspiracy, visa fraud, and money laundering counts in massive immigration fraud case. Full Story: dallasexpress.com/metroplex/7-ye…
The Dallas Express News tweet media
English
256
1.2K
3.1K
766.1K
P.E.M.B
P.E.M.B@0xPEMB·
PT2 - The website redirects to “rdtfyguioyughj[.]pages[.]dev” mimicking official Claude installation page. - Tricks user into running malicious cmd using “mshta”. Similar to campaign seen before by @k3yp0d
P.E.M.B tweet media
English
0
0
1
19
P.E.M.B
P.E.M.B@0xPEMB·
PT1-Malvertising Campaign Employing ClaudeFix? A malicious campaign targeting both Mac 🖥️ and Windows users to download and install a fake Claude AI. User: - Google searches “claude cli install” and it’s served with an ad to “hxxps://claude-code-update[.]squarespace[.]com”.
English
1
0
0
53
P.E.M.B
P.E.M.B@0xPEMB·
@k3yp0d Found another one rdtfyguioyughj[.]pages[.]dev
English
0
0
1
31
Simon Kenin
Simon Kenin@k3yp0d·
1/2 Claude Fix attacks both mac and windows claulastver.squarespace[.]com -> claude-code.official-version[.]com
Simon Kenin tweet media
English
2
3
17
2.2K
P.E.M.B
P.E.M.B@0xPEMB·
@RussianPanda9xx Same boat, lemme us know when you find out. Also I agree with the guy that said you have reached a peak.
English
0
0
1
20
RussianPanda 🐼 🇺🇦
RussianPanda 🐼 🇺🇦@RussianPanda9xx·
Man, I feel so old... I used to have all this passion, staying up all night reversing malware. Now I just watch 90 Day Fiancé straight after 5pm. Is it burnout or laziness?
GIF
English
94
1
503
56.8K
P.E.M.B retweetledi
tetsuo
tetsuo@tetsuoai·
tetsuo tweet media
ZXX
52
39
522
21.4K
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
🚨I HAVE LEAKED EVERY SINGLE PASSWORD EVER (4 to 32 chars long)! That is 347 novemdecillion passwords, the largest password leak ever! ALL of your passwords are in here, GUARANTEED! This is a client-side app, so what you search for is all local, never sent anywhere.
English
730
835
24.6K
5.4M