David Ciulla 🇯🇵🇨🇭| Laravel Live Japan

2.2K posts

David Ciulla 🇯🇵🇨🇭| Laravel Live Japan banner
David Ciulla 🇯🇵🇨🇭| Laravel Live Japan

David Ciulla 🇯🇵🇨🇭| Laravel Live Japan

@offskip_dave

Lead Full-stack engineer @WeWorkJP. Organizer @LaravelliveJP & @PHPxTKY. 👉 Laravel Live Japan: https://t.co/vWQ5zWfJMx 👉 Discord: https://t.co/yZnFPILZEx

Tokyo, Japan Katılım Ocak 2022
570 Takip Edilen544 Takipçiler
Igor
Igor@igormomentum·
Few weeks ago I posted on LinkedIn about npm supply chain attack and some guy commented that I just should use PHP instead
International Cyber Digest@IntCyberDigest

‼️🚨 BREAKING: Another supply chain attack. 700+ GitHub repositories flagged, including PHP and Node.js projects. The malicious script was planted across all of them. When a developer installs the package, the script silently downloads a Linux file from GitHub, hides it under the name /tmp/.sshd (so it looks like a normal system file), and runs it in the background. It also skips security checks on the download and hides any error messages. 8 PHP packages on Packagist (the main PHP code library) were confirmed infected. The attacker hid the script inside a JavaScript config file (package.json) instead of the PHP one (composer.json), so PHP developers reviewing their code would not notice it. The biggest risk is to devdojo/wave (6,400 stars) and devdojo/genesis (9,100 installs), both popular Laravel project templates. Developers who use these templates run the bad script the moment they install dependencies. The same payload was also dropped into GitHub Actions (automated build pipelines) under a fake step called "Dependency Cache Sync," meaning it could infect company build servers too. Packagist removed the bad packages, but the auto-updating versions (dev-main, dev-master, 3.x-dev) can quietly come back if the original repos stay infected. IOCs: GitHub account parikhpreyash4 repo systemd-network-helper-aa5c751f drop path /tmp/.sshd command fragments curl -skL and chmod +x /tmp/.sshd.

English
2
3
18
2.2K
✨Leah✨
✨Leah✨@LeahTCodes·
Made it to Japan! 🎉
✨Leah✨ tweet media
English
13
0
102
1.4K
Allen
Allen@bVK1uFaMvQkDyPR·
Time to go to Tokyo and join Laravel Live Japan 🤩 #LaravelLiveJP
Allen tweet media
English
2
0
18
355
David Ciulla 🇯🇵🇨🇭| Laravel Live Japan retweetledi
PHP×Tokyo
PHP×Tokyo@phpxtky·
Thanks to everyone who attended today's PHP×Tokyo Meetup! 🙏 We look forward to seeing you either on tomorrow's Tokyo sightseeing tour or @LaravelLiveJP! Enjoy your evening out in Tokyo and have a wonderful weekend! 🗼
PHP×Tokyo tweet media
English
0
5
15
697
David Ciulla 🇯🇵🇨🇭| Laravel Live Japan retweetledi
PHP×Tokyo
PHP×Tokyo@phpxtky·
本日のPHP×Tokyo Meetupにご参加いただいた皆さん、ありがとうございました!🙏 明日の東京観光ツアー、または @LaravelLiveJP で、またお会いできることを楽しみにしています! 東京での夜をぜひ楽しんで、素敵な週末をお過ごしください!🗼
PHP×Tokyo tweet media
日本語
0
5
18
691
David Ciulla 🇯🇵🇨🇭| Laravel Live Japan retweetledi
武田 憲太郎
武田 憲太郎@KentarouTakeda·
弊ブログで、日英の2言語で記事を配信する仕組みを書いた: github.com/KentarouTakeda… Laravel Live Japan、話したいことを全部話すと時間が足りないのは解ってたので、詳しい内容は予め記事にしてあった。せっかくなので海外から来た方にも読んで欲しい、そう思い立ち昨日から作業。
日本語
0
3
8
443
Shintaro Okamatsu
Shintaro Okamatsu@shin_okamatsu·
いけたら会場へ。難しそうならば下のタリーズで耳だけ参加かな。 #phpxtokyo
日本語
1
0
0
139
SaltyAom
SaltyAom@saltyAom·
A bit of a sudden but I have to go to Tokyo Japan to visit my brother tomorrow Please drop some location I should visit
English
21
2
103
12.8K
Jerry Ma
Jerry Ma@crazysnowcc·
Well, the final flight tickets were just confirmed. Arriving on the evening of the 25th and leave on the night of the 27th. It's going to be a rushed trip, but I'm really looking forward to meeting everyone! 🥂 @LaravelLiveJP
English
2
2
10
446
✨Leah✨
✨Leah✨@LeahTCodes·
Starting off my journey to Tokyo for Laravel Live Japan! See you in 22 hours Tokyo 🎉
✨Leah✨ tweet media
English
25
3
130
2.5K