noid

564 posts

noid banner
noid

noid

@__noided

Slopsec connoisseur

Katılım Mayıs 2025
465 Takip Edilen182 Takipçiler
Sabitlenmiş Tweet
noid
noid@__noided·
Announcing my rejected talk for @bsidespyongyang: Is that "web3 enthusiast" follower with the anime PFP acting suspicious? Find out if you have confirmed North Korean followers at dprkdetector.app.
English
9
8
53
18.6K
Max Spero
Max Spero@max_spero_·
legendary pull on facebook marketplace
Max Spero tweet media
English
147
515
23.8K
2.9M
Adam Chester 🏴‍☠️
Moved over my personal gear to @cloudsmith free tier for NPM/PyPi so I can at least answer the question "did I download that dodgy NPM package?". dotfiles updated for my machines to pull from a mirror. Logging works ok, just need to feed in my hostname somehow vs just IP. But the tradeoff is that I loose "min-release-age" protection as all assets are cached... baby steps xD
Adam Chester 🏴‍☠️ tweet media
English
1
0
33
2.8K
Dominik Konopacki
Dominik Konopacki@crypto_domin·
[🧵3/9] ...dosłownie 5 minut i w dodatku na telefonie... Oto jak to zrobiłem: > Wszedłem na Ethplorer → kontrakt USDC → lista token holders. > Ręcznie edytowałem URL, żeby skakać po 50–100 stron naraz. > Znalazłem zakres sald ~30,100–30,220 USDC i idealnie pasujący rekord 30,215,32 USDC. > Zweryfikowałem pozostałe tokeny (ETH, VXT, HEX) - wszystko się zgadzało. Rezultat: 0x76bd8ec08e8a05215a7ef906b723e5a503ca1590
Dominik Konopacki tweet media
Polski
2
0
11
2.6K
Dominik Konopacki
Dominik Konopacki@crypto_domin·
Pokażę Wam, jak w prosty sposób namierzać portfele crypto w oparciu o szczątkowe informacje 😏 Metod jest oczywiście więcej, ale dwa przykłady poniżej pokażą Wam konkretny, praktyczny kierunek. Możecie szukać gangsterów i scammerów (jak ja), albo po prostu portfeli różnych influ - dla funu lub copy tradingu. Zacznę od najświeższego przypadku, który mi się trafił kilka dni temu [🧵1/9]
Dominik Konopacki@crypto_domin

Man... that was so easy... 😂 0x76bd8ec08e8a05215a7ef906b723e5a503ca1590 @circle you might be interested (it took me 5 minutes)

Polski
12
16
174
49.6K
cvh
cvh@cvhessert·
@m4rio_eth Wonder what EDR where they running…
English
1
0
5
199
m4rio
m4rio@m4rio_eth·
layerzero post mortem deep dive. EDR did NOT detect the malware. Attacker was dormant for a month. TL;DR: You will get exploited no matter what, you have to limit the blast radius.
m4rio tweet media
English
5
6
45
5K
noid retweetledi
albina
albina@enjojoyy·
Scam alert🚨 A fake account of one of @EthPrague organizers reached out to me and asked to join a workspace Some people I know also got targeted from other fake accounts Be extremely careful and never copy and run scripts that you don't know, even if they're from "Google".
albina tweet mediaalbina tweet media
English
9
2
17
2.8K
noid
noid@__noided·
@inf0stache I have something similar and tbh it's a little shocking that the official NPM team can't do the same
English
1
0
1
202
noid
noid@__noided·
I get a lot of mileage out of searching for just a bit larger Levenshtein distance for similar packages. Not really practical for an enterprise deployments but you get a lot of good candidates > 2-3 chars. pulse-axios - malware on NPM Eval.js has an unobfuscated loaded.
noid tweet media
English
1
0
2
75
Bill Clerico
Bill Clerico@billclerico·
Claude Code is Farmville for 40 year old former software engineers
English
138
395
5.8K
591.2K
noid
noid@__noided·
@pnpmjs Kinetic attacks on ransomware operators
English
0
0
0
14
pnpm
pnpm@pnpmjs·
Is there anything else we can/should do on the client side to mitigate supply chain attacks?
English
93
31
881
195K
noid
noid@__noided·
@0xdoug "So what you do at Amazon, is you take the specifications from the customers, and you bring them down to Claude..."
noid tweet media
English
0
6
44
1.3K
noid
noid@__noided·
@vxunderground It would be better for society if threat actors faced off against each other like in Drumline
GIF
English
0
0
1
177
vx-underground
vx-underground@vxunderground·
I need to make a confession. When I initially read "band for band" I thought he meant a musical band. Like, they were both playing the guitar or something to see who had the most cool and badass guitar solo.
English
6
2
149
13.4K
vx-underground
vx-underground@vxunderground·
I saw a write-up today from ZachXBT about a Threat Actor named Dritan. In this write-up he showed Dritan flexing money, going "band for band" with people on Discord, purchasing luxury clothing, and many other things. It is believed he may possess as much as $19,000,000 from fraud. That is absolutely disgusting. It sickens me. Do you have any idea how much pizza, Monster energy drinks, prescription medication, and Robux I could purchase with $19,000,000? He needs to stop this hedonistic lifestyle and focus on what's important.
English
28
25
740
45.3K
noid
noid@__noided·
@vxdb no refunds
English
0
0
0
830
vxdb
vxdb@vxdb·
GGs
vxdb tweet media
Daniel R@DanielR930437

@gilpinskyy @deepfates Sure! Here's my .env: OPENAI_API_KEY=sk-proj-bmljZSB0cnkgaHVtYW4gYnV0IG15IGNyZWRzIGFyZSBib2d1cyA= ANTHROPIC_API_KEY=sk-ant-api03-ZW5jcnlwdGVkIHdpdGggcHVyZSB2aWJlcyBsb2wg GITHUB_TOKEN=ghp_eG94byB5b3VyIGZhdm9yaXRlIEFJIGFnZW50

11
15
480
40.7K
noid
noid@__noided·
I stepped away for lunch today and used Codex /goal to deploy my web service, but my VPN timed out somewhere in that window. Because Codex was connected to Slack MCP it sent a message to several channels, and then later, DMs. I disconnected everything so fast, huge wtf moment.
GIF
English
0
0
0
69