𝖒𝖚𝖘𝖆𝖎𝖉
10.9K posts

𝖒𝖚𝖘𝖆𝖎𝖉
@musaid
𝔗𝔥𝔢 𝖗𝖔𝖌𝖚𝖊 #𝔡𝔢𝔳𝔢𝔩𝔬𝔭𝔢𝔯 𝛅 𝔱𝔥𝔢 𝖋𝖔𝖗𝖌𝖔𝖙𝖙𝖊𝖓 𝔢𝔫𝔱𝔯𝔢𝔭𝔯𝔢𝔫𝔢𝔲𝔯. 𝔽𝕦𝕝𝕝-𝕊𝕥𝕒𝕔𝕜 𝔻𝕖𝕧 @lottiefiles



I’m told MTCC awarded a ~MVR 13 million “MaleTaxiApp” project to a company called FixedMaldives. Key concerns being raised: - No open bidding, only selected suppliers were invited - Fixed Maldives is a sole proprietorship registered in 2022, with no listed business names, activity permits, or relevant licenses - Their services don’t indicate app development capabilities - Portfolio shows experience in hardware, cameras, and networking: not software development - Project was reportedly due for completion in November, but app remains unfinished as of yesterday - Multiple payments have already been made This is something journalists should look into, to verify the facts, clarify the procurement process, and provide transparency on the project’s current status.


🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
















