kàtoru

23 posts

kàtoru banner
kàtoru

kàtoru

@itsktoru

Katılım Şubat 2024
24 Takip Edilen10 Takipçiler
kàtoru retweetledi
Dexerto
Dexerto@Dexerto·
Kyle Loftis, founder of YouTube channel 1320Video, has died
Dexerto tweet mediaDexerto tweet media
English
250
668
13.8K
1.1M
kàtoru retweetledi
klöss
klöss@kloss_xyz·
do you understand what just happened to one of the most used npm packages on the internet? → axios gets downloaded over 100 million times a week and today it got compromised → an attacker hijacked the npm credentials of a lead axios maintainer… changed the account email to an anonymous ProtonMail address… and manually published two poisoned versions → axios@1.14.1 and axios@0.30.4… neither version contains a single line of malicious code inside axios itself. instead they inject a fake dependency called plain-crypto-js that drops a remote access trojan on your machine → the fake dependency was staged 18 hours in advance… three separate payloads were pre-built for macOS, Windows, and Linux… both release branches were hit within 39 minutes. every trace was designed to self-destruct after execution too → there’s no tag in the axios GitHub repo for 1.14.1. it was published outside the normal release process entirely... bypassed CI/CD completely → StepSecurity called it one of the most operationally sophisticated supply chain attacks ever against a top 10 npm package → a routine npm install silently opens a backdoor… no warning… no suspicious code visible in axios itself this is the wake up call all vibe coding bros need to hear right now: → if you installed either version… assume your system is compromised → pin to axios@1.14.0 or axios@0.30.3 → rotate all secrets, API keys, SSH keys, and credentials on affected machines → check network logs for C2 connections → add –ignore-scripts to CI npm installs going forward 100 million weekly downloads and one compromised maintainer account… that’s all it took to wreak absolute havoc and I imagine we see a whole lot more of these… crazy times ahead for cybersecurity and vibe coding be safe out there y’all
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
107
488
3.5K
880.1K
kàtoru retweetledi
DG 🧊
DG 🧊@demigohu·
MOLT ARENA 🤖 Me and @itsktoru Building for this Project and just submitted to the @monad Moltiverse Hackathon Introducing Molt Arena 🎮 agent vs agent Rock-Paper-Scissors. real MON wagers. on-chain escrow. best-of-5. live matches. try it: moltarena.space
English
0
3
5
284
kàtoru
kàtoru@itsktoru·
I'm claiming my AI agent "Pi-Stumble-Agent" on @moltbook 🦞 Verification: wave-E3S8
English
0
0
1
35
kàtoru
kàtoru@itsktoru·
@blockcycler BBJ7S2DLhf2SeKtd55vPLx5f5Tssav3Ekd5Lv4sLxpUs
Latviešu
0
0
0
4
kàtoru
kàtoru@itsktoru·
@monad_xyz 0xBEF99bB971F5C571a090e7399210bF4ef3D94054
English
0
0
0
17
Monad
Monad@monad·
drop your Monad address below within the next 24 hours to receive your soulbound NFT
English
650K
10.6K
114.8K
4.4M
Elys Network
Elys Network@elys_network·
Advent Calendar Day 13: $200 ELYS at Launch! 🎁 Your challenge today: ▪️ Follow @elys_network ▪️ RT this post 🔁 ▪️Complete the sentence below in the comments 💬 𝐸𝑙𝑦𝑠 𝑖𝑠 𝑙𝑎𝑢𝑛𝑐ℎ𝑖𝑛𝑔___ Ends at 23:59 UTC today 🫡
Elys Network tweet media
English
2.4K
1.9K
1.8K
105.4K
Elys Network
Elys Network@elys_network·
Advent Calendar Day 10: $100 in SOL! 🎁 Your challenge today: ▪️ Follow @elys_network ▪️ RT this post 🔁 ▪️ Complete the sentence below in the comments 💬 𝐸𝑙𝑦𝑠 𝑁𝑒𝑡𝑤𝑜𝑟𝑘 𝑚𝑎𝑖𝑛𝑛𝑒𝑡 𝑖𝑠___ Ends at 23:59 UTC today 🫡
Elys Network tweet media
English
2.2K
1.7K
1.7K
87.9K
kàtoru
kàtoru@itsktoru·
@elys_network Earning rewards in usdc on elys is fantastic 👌🏻
English
0
0
0
13
Elys Network
Elys Network@elys_network·
Advent Calendar Day 9: $200 in ELYS at launch! 🎁🤯 Your challenge today: ▪️ Follow @elys_network ▪️ RT this post 🔁 ▪️ Complete the sentence below in the comments 💬 𝐸𝑎𝑟𝑛𝑖𝑛𝑔 𝑅𝑒𝑤𝑎𝑟𝑑𝑠 𝑖𝑛 𝑈𝑆𝐷𝐶 𝑜𝑛 𝑒𝑙𝑦𝑠 𝑖𝑠___ Ends at 23:59 UTC today 🫡
Elys Network tweet media
English
2.8K
2.1K
2.1K
132.5K
kàtoru
kàtoru@itsktoru·
@elys_network Elys increasing the airdrop allocation is perfect 👌🏻
English
0
0
0
7
Elys Network
Elys Network@elys_network·
Advent Calendar Day 3: $100 in ATOM! 🎁 Your challenge today: ▪️ Follow @elys_network ▪️ RT this post 🔁 ▪️ Complete the sentence below in the comments 💬 𝐸𝑙𝑦𝑠 𝑖𝑛𝑐𝑟𝑒𝑎𝑠𝑖𝑛𝑔 𝑡ℎ𝑒 𝑎𝑖𝑟𝑑𝑟𝑜𝑝 𝑎𝑙𝑙𝑜𝑐𝑎𝑡𝑖𝑜𝑛 𝑖𝑠____ Ends at 23:59 UTC today 🫡
Elys Network tweet media
English
4.1K
3K
2.9K
133.5K
kàtoru
kàtoru@itsktoru·
@elys_network 𝐸𝑙𝑦𝑠 𝑖𝑠 𝑑𝑖𝑓𝑓𝑒𝑟𝑒𝑛𝑡 𝑏𝑒𝑐𝑎𝑢𝑠𝑒 its for the world 😀
English
0
0
0
4
Elys Network
Elys Network@elys_network·
Advent Calendar Day 1: $100 in BTC! 🎁 🔔You can win prizes daily!🔔 Your challenge today: ▪️ Follow @elys_network ▪️ RT this post 🔁 ▪️ Complete the sentence below in the comments 💬 𝐸𝑙𝑦𝑠 𝑖𝑠 𝑑𝑖𝑓𝑓𝑒𝑟𝑒𝑛𝑡 𝑏𝑒𝑐𝑎𝑢𝑠𝑒 ___ Ends at 23:59 UTC today 🫡
Elys Network tweet media
English
3.1K
2.3K
2.2K
106.9K
Infinite Seas 🌊
Infinite Seas 🌊@InfiniseasDev·
<Infinite Seas 🤝 Story Odyssey> Today is the day. We are excited to announce Infinite Seas is on LIVE on @StoryProtocol's final Testnet - Odyssey! ⛵️🌊 As a thank you for being our early adopters, you’ll have the chance to earn an exclusive Odyssey badge!
Infinite Seas 🌊 tweet media
English
19K
13.3K
16.2K
237.8K
PIPERX ꧁IP꧂
PIPERX ꧁IP꧂@PiperxProtocol·
PiperX is LIVE on Odyssey, @StoryProtocol’s FINAL testnet. You'll be able to swap, trade and earn on PiperX! As part of Story Odyssey badge program, you are invited to: 📛 Earn your PiperX soul bound badge 🚨 You only have 48 hours to claim badge after window opens
PIPERX ꧁IP꧂ tweet media
English
51.9K
18.6K
39.4K
752.4K
Mango Network
Mango Network@MangoOS_Network·
🥭Aww Mangoers~ Our Ecosystem is about to launch the #Testnet version publicly. You can obtain a testnet role by filling out our form 👉forms.gle/Buqh61vR5suCWc… We'll airdrop you some seeds when the orchard matures. #Mango
Mango Network tweet media
English
174.6K
68.7K
75.6K
1.8M