Tomislav Pericin

1.5K posts

Tomislav Pericin banner
Tomislav Pericin

Tomislav Pericin

@ap0x

CSA at ReversingLabs LLC. Designs file analysis platforms, engines and reverse engineering tools for fun. Something about unpacking and PE file format.

Republic of Croatia Katılım Kasım 2008
485 Takip Edilen1.7K Takipçiler
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
🚨Versions 2.6.2 and 2.6.3 of the PyPI package "lightning" are compromised. RL research note: It is the same type of #Shaihulud malware as in recent Bitwarden and SAP compromises.
English
4
3
3
453
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
It looks like #TeamPCP has again compromised @Checkmarx #VSCode extensions and @Docker images. Newly published VSCode extensions checkmarx.cx-dev-assist (1.17.0 & 1.19.0) and checkmarx.ast-results (2.63.0 & 2.66.0) contain malicious code.
English
2
7
27
4K
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
🚨 RL Research Alert! Look out for the compromised versions 1.14.1 and 0.30.4 of axios npm package with almost 11 billion downloads. secure.software/npm/packages/a…
English
1
3
7
401
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
👁️ Be on the look out for compromised versions 1.82.7 and 1.82.8 of the "litellm" PyPI package, which has more than 479 million downloads 🧵👇 secure.software/pypi/packages/…
English
4
6
12
1.2K
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
🚨 RL researchers occasionally come across interesting techniques used by malware in the wild. One such campaign consisting of 10 packages uses @github gists as a host for the second-stage payload. @cloudsop/hmoment" target="_blank" rel="nofollow noopener">secure.software/npm/packages/@…
English
1
3
4
612
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
⚠️🧵RL researchers have discovered a malicious #VSCode extension with over 12K installs that has been dormant since December, but now ships a malicious version: secure.software/vscode/package…
English
1
3
6
344
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
👀Blog with full details & more updates can be found here: reversinglabs.com/blog/another-s… #npm #OSS #SoftwareSupplyChainSecurity #Shaihulud @ap0x
ReversingLabs@ReversingLabs

RL automated threat detection system is detecting a new wave of Shai-hulud #npm packages. Look out for RL's TH15502 policy violation in npm packages. The campaign affects popular [@]asyncapi packages with millions of downloads. Here is an example - @asyncapi/specs/6.8.3" target="_blank" rel="nofollow noopener">secure.software/npm/packages/@…

English
0
3
5
1.6K
Tomislav Pericin
Tomislav Pericin@ap0x·
@ReversingLabs This new worm variant includes wiper functionality. Shai-hulud permanently destroy all data in the user's home directory making it unrecoverable. It overwrites the free space where the deleted files used to be. Ensuring that data recovery software cannot restore the files.
English
0
0
0
102
Tomislav Pericin
Tomislav Pericin@ap0x·
@ReversingLabs Just like with the first wave, automated dependency management tools (like DependaBot) are creating pull requests that are helping the worm spread.
English
1
0
0
99
Tomislav Pericin
Tomislav Pericin@ap0x·
RL automated threat detection systems are detecting the new wave of Shai-Hulud npm packages. Look out for the TH15502 policy violation in our Spectra Assure Community. Here is an example of a compromised package: @asyncapi/specs/6.9.1" target="_blank" rel="nofollow noopener">secure.software/npm/packages/@… - More info to follow from @ReversingLabs
English
1
1
1
415
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
After detecting & mitigating multiple supply chain attacks targeting #OSS the past few weeks, RL co-founder & CSA @ap0x had a gut reaction: "Something has to change, because we can’t keep doing this every week." #npm #GitHub bit.ly/426pOAC
English
0
1
2
338
Tomislav Pericin retweetledi
ReversingLabs
ReversingLabs@ReversingLabs·
⚠️ RL researchers have found another package compromised on day 3 of the ongoing #npm #phishing campaign. It hides the obfuscated payload in the middle of an already large index.js file.👇 bit.ly/42mEyLu
English
0
2
7
397