Akintomiwa⚡

7.6K posts

Akintomiwa⚡ banner
Akintomiwa⚡

Akintomiwa⚡

@OfficiallyXenos

ML & Blockchains.|| Pharmacist

in my head Katılım Ekim 2018
851 Takip Edilen762 Takipçiler
Akintomiwa⚡ retweetledi
Demola
Demola@DAMOZPIXIE1·
The invitation from Keila Rosa Garcia Arrieta appeared to be a professional opportunity to upgrade a Web3 social platform from v1 to v2. The project description was detailed, mentioning partnerships with CryptoOasis and a roadmap involving real estate DApps, multi-staking, and AI integrations. The client even provided a high-fidelity Figma design link, making the offer look like a legitimate, high-stakes engineering task. The trap was set within the next step of the interview process. The client requested that I download the MVP v1 repository from a Dropbox link to "familiarize myself with its structure" before meeting with a technical manager. To make the scam more convincing, the folder included the actual Figma design files, creating a false sense of security while looking for technical context. I decided to manually inspect the repository files before running any installation commands. This caution saved my entire infrastructure. Inside the next.config.js file, the code initially looked like a standard Next.js configuration for image whitelisting. However, I discovered a hidden, malicious string on the very first line that was intentionally pushed far to the right so it would be cut off in most code editors. This hidden script used a classic malware pattern. It utilized atob() to decode a Base64 string into a URL, fetch() to download a remote payload, and eval() to execute that payload. Because Next.js config files run automatically during the build process, simply typing npm install or npm run dev would have granted the attacker full execution rights on my machine. The goal of these "job interview" repos is to exfiltrate high-value developer data. They target your ~/.ssh folder, GitHub tokens, AWS credentials, and browser-based crypto wallets like MetaMask. It is a highly effective social engineering attack because it hides behind a professional-looking job description and a legitimate Figma design. Despite reporting this clear threat to Upwork, their Trust & Safety team responded stating they "didn't find a violation of Upwork's policies" and considered the matter closed. This is a dangerous oversight. It means the platform may not be catching sophisticated malware hidden in configuration files, even when it's specifically designed to bypass standard detection. The lesson is clear: you are your own last line of defense. Never trust a repository from a new client, even if it looks legitimate and the platform clears the account. Always search the codebase for the combination of fetch, atob, and eval before you ever initialize a project.
Demola tweet mediaDemola tweet mediaDemola tweet mediaDemola tweet media
English
2
1
4
470
OlúwatúnmiṣeSavesTheNight 🖤
OlúwatúnmiṣeSavesTheNight 🖤@OluwatunmiseMi8·
My watch has now ended. B.A German, University of Ibadan. Der Ruhm, die Klarheit und der Segen gehören mir immer weiter.💐🤌🏾
OlúwatúnmiṣeSavesTheNight 🖤 tweet mediaOlúwatúnmiṣeSavesTheNight 🖤 tweet mediaOlúwatúnmiṣeSavesTheNight 🖤 tweet mediaOlúwatúnmiṣeSavesTheNight 🖤 tweet media
Deutsch
24
77
532
16.1K
Akintomiwa⚡
Akintomiwa⚡@OfficiallyXenos·
people are now just tweeting "... if only there was a tool", only to build and launch the damn tool the next day😅😭
English
0
0
0
28
Demola
Demola@DAMOZPIXIE1·
@Bhavani_00007 Deadline. Client. Bug. Infinite loop. Race condition.
English
1
0
1
15
Bhavani.py
Bhavani.py@Bhavani_00007·
I am a Vibe Coder, scare me with one word
Bhavani.py tweet media
English
1.2K
38
1.8K
152.2K
Ifihan 👩🏾‍🍳🛠️
Another project. Just because I can 🤏🏽😂 Using mock data for now. Backend is almost ready! This one means a lot to me 🥹
English
16
28
350
11.8K
Akintomiwa⚡ retweetledi
Zainab Lawal
Zainab Lawal@Zeeskylaw·
So, I built this with Media Pipe.🫡 It’s a Chrome Extension that uses your webcam to detect when you struggle to read. 😑 Squint → Zoom In 😳 Open Wide → Zoom Out It's currently calibrated just for my face/eyes. If there's enough demand, I’ll try to generalize the calibration or add some setup and launch it on the Chrome Web Store for everyone. Let me know if you’d use it (Tech stack & Architecture in the comments 🧵)
Devin Goble@devinbgoble

@loftwah Who's building the AI powered browser extension that detects when you squint and lean in, and increases the zoom?

English
25
54
249
18.3K
Akintomiwa⚡ retweetledi
Demola
Demola@DAMOZPIXIE1·
The Billboard and Dashboard sections are fully operational, featuring the Global Map for minting, real-time Stats & Trends, a competitive Leaderboard, and a comprehensive Asset portfolio view. The Community hub drives engagement through a resale Marketplace, a gamified Quests & Airdrop system, and an exclusive token-gated Whale Chat that unlocks for pixel owners. #VectixBoard #Solana #MSImagineCup #BuildInPublic #Web3 #DigitalIdentity #Supabase #NextJS #IndieDev #BlockchainGaming
English
0
1
2
143
Akintomiwa⚡ retweetledi
Demola
Demola@DAMOZPIXIE1·
Introducing VectixBoard: A decentralized billboard built on Solana. 1,000,000 pixels. 100% On-Chain. The Grid is infinite. Ownership is forever. 🌐✨ #Solana #Web3
English
0
1
2
183
Zainab Lawal
Zainab Lawal@Zeeskylaw·
I’m starting 2026 by writing an Ethics paper on why 'Big Pharma' is actually the hero of the modern world. If my professor gives me a bad grade, I’ll pull a Fulnecky: Cry on YouTube, and try to get them fired. 😑
Zainab Lawal tweet media
English
4
2
33
1.3K
Akintomiwa⚡ retweetledi
Demola
Demola@DAMOZPIXIE1·
From a basic grid to a pro dashboard, turning digital real estate into a proper platform. 💎⚡️ #Solana #SolanaNFT
Demola tweet mediaDemola tweet media
English
0
1
1
64
Akintomiwa⚡
Akintomiwa⚡@OfficiallyXenos·
@jobosonchisa Damn, they come late to their shows?? That's sad. And they are the only guys i can swear that i will pay to watch anywhere in the world. Damn again sha.
English
2
0
2
765
Chisa
Chisa@jobosonchisa·
Got mad love for SDC. But I’m afraid my patience for waiting over 4 hours for headline artistes to come on stage has run out. Starting a yearly concert late three times in a row isn’t a coincidence. Won't be loving myself attending their shows when they fail to keep to time.
English
7
14
98
10.2K
Akintomiwa⚡
Akintomiwa⚡@OfficiallyXenos·
Context: I was robbed and the thieves were able to access my GTBank app but not my Opay. What a 2025 man.
English
5
0
0
59
Akintomiwa⚡
Akintomiwa⚡@OfficiallyXenos·
To think that i put virtually all my money in my GTBank thinking it was more secure than my Opay. I no fit wrap my head around the ease that account was penetrated man. 😤
English
7
0
1
197
Akintomiwa⚡ retweetledi
Demola
Demola@DAMOZPIXIE1·
Just completed the ASI Autonomous Agents Platform for the ASI Alliance Hackathon. The platform features three autonomous agents in healthcare, finance, and logistics. They communicate in real time using the Chat Protocol and MeTTa Knowledge Graph. Live demo: asi-frontend.onrender.com Source code: github.com/SemiuAdesina/a… Built with Fetch.AI uAgents and SingularityNET MeTTa. #ASIAlliance #AutonomousAgents #FetchAI #SingularityNET
English
0
1
1
102