Tim⚫

20.4K posts

Tim⚫ banner
Tim⚫

Tim⚫

@TDraw75

Believe in Jesus. Make sure you have great people you are around. Never give up. If you don't quit, you win. Keep growing.

Katılım Mart 2024
1.6K Takip Edilen1.3K Takipçiler
Tim⚫
Tim⚫@TDraw75·
@OceanXRP_ @jo5htheboss God forbid we have a lil motion white boy. 4yDSFNMitxy6waXPTkPyyVvbbQSiqe7zD1VxnzEypump
Tim⚫ tweet media
Suomi
0
0
1
8
Ocean ◽️
Ocean ◽️@OceanXRP_·
📝 I don’t have time for hating because I’m to busy making moves.
Ocean ◽️ tweet media
English
8
3
26
509
Tim⚫ retweetledi
Cigtoshi Ⓜ️🌊
Cigtoshi Ⓜ️🌊@mikeyleo_00·
all great convictions, undoubtedly billions you should check out motion, I genuinely believe we can get there as long as we keep building the community and putting out quality content the way we are the more we grow, the more creatives we onboard, the better the content gets, it becomes a flywheel of success we have the foundation, we have the ingredients everyone wants $motion
English
6
4
14
116
Shadow
Shadow@_Shadow36·
As the trenches continue to ruin itself I find comfort in buying these established memes at a discount. Very rarely is anything new interesting. Nothing creative or innovative. We are fast tracking to zero. Rather save my money or buy shit that I truly believe in only. Shorting the trenches, longing community. We are the only ones who can change this shit.
English
143
32
243
14.4K
Tim⚫
Tim⚫@TDraw75·
@ANIMEGEMSS God forbid you bid a little motion. 4yDSFNMitxy6waXPTkPyyVvbbQSiqe7zD1VxnzEypump
Tim⚫ tweet media
Suomi
0
0
0
15
ANIME
ANIME@ANIMEGEMSS·
WHAT WE APING ?
English
85
1
75
5.9K
Tim⚫
Tim⚫@TDraw75·
@NetflixAnime When next part of the four knights of the apocalypse?
English
0
0
0
6
Netflix Anime
Netflix Anime@NetflixAnime·
We've got MORE anime coming your way! Check these out on Netflix this April and May 👀
Netflix Anime tweet mediaNetflix Anime tweet media
English
4.8K
377
8.7K
2M
Jobonsol
Jobonsol@LeQuantae·
Is this not crazy... A Chocolate company accidentally spiked their products with Viagra??? After the KitKat situation this is going to go viral... $BBC - Big Black Chocolate
R A W S A L E R T S@rawsalerts

🚨#BREAKING: A California Chocolate company has issued a nationwide recall after it chocolate products was spiked with Viagra ingredients.

English
5
3
6
752
R A W S A L E R T S
R A W S A L E R T S@rawsalerts·
🚨#BREAKING: A California Chocolate company has issued a nationwide recall after it chocolate products was spiked with Viagra ingredients.
English
1K
1.1K
8K
1.3M
Tim⚫ retweetledi
.
.@Sagishidev·
INSANE NEWS , one of the most used npm packages with over 100m weekly downloads just got hacked. This npm powers a lot of major websites like Tiktok, Chevron, Upwork Ca:74zHiVFed825s2NJmvhxXkMmdHZkg3eSr54jTNdVpump Dex at 15k cashback x.com/i/trending/203… x.com/search?q=axios…
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
3
1
3
1.7K
Tim⚫
Tim⚫@TDraw75·
$Axios in undervalued. 74zHiVFed825s2NJmvhxXkMmdHZkg3eSr54jTNdVpump
klöss@kloss_xyz

do you understand what just happened to one of the most used npm packages on the internet? → axios gets downloaded over 100 million times a week and today it got compromised → an attacker hijacked the npm credentials of a lead axios maintainer… changed the account email to an anonymous ProtonMail address… and manually published two poisoned versions → axios@1.14.1 and axios@0.30.4… neither version contains a single line of malicious code inside axios itself. instead they inject a fake dependency called plain-crypto-js that drops a remote access trojan on your machine → the fake dependency was staged 18 hours in advance… three separate payloads were pre-built for macOS, Windows, and Linux… both release branches were hit within 39 minutes. every trace was designed to self-destruct after execution too → there’s no tag in the axios GitHub repo for 1.14.1. it was published outside the normal release process entirely... bypassed CI/CD completely → StepSecurity called it one of the most operationally sophisticated supply chain attacks ever against a top 10 npm package → a routine npm install silently opens a backdoor… no warning… no suspicious code visible in axios itself this is the wake up call all vibe coding bros need to hear right now: → if you installed either version… assume your system is compromised → pin to axios@1.14.0 or axios@0.30.3 → rotate all secrets, API keys, SSH keys, and credentials on affected machines → check network logs for C2 connections → add –ignore-scripts to CI npm installs going forward 100 million weekly downloads and one compromised maintainer account… that’s all it took to wreak absolute havoc and I imagine we see a whole lot more of these… crazy times ahead for cybersecurity and vibe coding be safe out there y’all

Dansk
0
0
2
128
Tim⚫ retweetledi
klöss
klöss@kloss_xyz·
do you understand what just happened to one of the most used npm packages on the internet? → axios gets downloaded over 100 million times a week and today it got compromised → an attacker hijacked the npm credentials of a lead axios maintainer… changed the account email to an anonymous ProtonMail address… and manually published two poisoned versions → axios@1.14.1 and axios@0.30.4… neither version contains a single line of malicious code inside axios itself. instead they inject a fake dependency called plain-crypto-js that drops a remote access trojan on your machine → the fake dependency was staged 18 hours in advance… three separate payloads were pre-built for macOS, Windows, and Linux… both release branches were hit within 39 minutes. every trace was designed to self-destruct after execution too → there’s no tag in the axios GitHub repo for 1.14.1. it was published outside the normal release process entirely... bypassed CI/CD completely → StepSecurity called it one of the most operationally sophisticated supply chain attacks ever against a top 10 npm package → a routine npm install silently opens a backdoor… no warning… no suspicious code visible in axios itself this is the wake up call all vibe coding bros need to hear right now: → if you installed either version… assume your system is compromised → pin to axios@1.14.0 or axios@0.30.3 → rotate all secrets, API keys, SSH keys, and credentials on affected machines → check network logs for C2 connections → add –ignore-scripts to CI npm installs going forward 100 million weekly downloads and one compromised maintainer account… that’s all it took to wreak absolute havoc and I imagine we see a whole lot more of these… crazy times ahead for cybersecurity and vibe coding be safe out there y’all
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
107
488
3.5K
862K
Tim⚫ retweetledi
vx-underground
vx-underground@vxunderground·
There is a project on GitHub called Axios. Axios is extremely popular. It is used by millions upon millions of applications. Axios is a programming library that helps your JavaScript code make HTTP/S requests (communicate with websites). In simple terms, if you're a programmer doing something with JavaScript, and want to do stuff that communicates with a website in literally any capacity, people heavily recommend using Axios due to its simplicity. Using Axios you don't have to reinvent the wheel and do a bunch of work. All you need to do is import Axios into your code and you're off to the races. Someone (currently unknown) compromised Axios (currently unknown how) to deliver malware to people. When someone updates or installs Axios, Axios itself contains malware. What the malware does is (currently) unknown, but it is being reversed engineered by probably every malware analyst on the planet at this moment. In a few hours more details will emerge. Information is being exchanged in real time on social media and private communication platforms as I write this. Due to the size and popularity of Axios, it is unknown how many are impacted, it could be millions, it could be thousands, or if we're lucky, only hundreds of people or organizations will be impacted. If this is absolute worst case scenario, millions of organizations across the planet have been infected with malware which (currently) we do not understand. However, the likelihood of this is low. It appears Axios being compromised was detected quickly, potentially within minutes (or hours) of it being compromised to deliver malware. Additionally, the likelihood of every single Axios user updating Axios as soon as it was compromised to deliver malware is astronomically low. It is basically zero. The impact from Axios being compromised is devastating, the fallout from this will be a massive headache. This is unironically a malware nuclear missile and will likely be studied in the future.
English
108
845
7.8K
580.5K
Tim⚫
Tim⚫@TDraw75·
Big deal 💯. 74zHiVFed825s2NJmvhxXkMmdHZkg3eSr54jTNdVpump
MotiAI@Cyl0nFrak

Axios için kritik uyarı: Yeni axios@1.14.1 sürümünün bugün ortaya çıkan plain-crypto-js@4.2.1 paketini çektiği ve bunun zararlı yazılım içerdiği söyleniyor. Axios kullananlar sürümü hemen sabitlesin, lockfile’larını kontrol etsin ve şimdilik güncelleme yapmasın.

Dansk
0
0
0
33
Itskuro
Itskuro@its_kuroo_sol·
Imagine installing a normal app but it secretly installs something else in the background that can run commands on your computer, that’s what is happening right now with axios ??
English
2
0
3
375