
15.8K posts

@sitnikcode
Author of @PostCSS. Russian: @andrey_sitnik 🦋 @en.sitnik.es 🐘 @[email protected]








🚨 We’ve confirmed the intercom-client@7.0.4 was compromised in the ongoing Mini Shai-Hulud worm attack. The npm package includes a malicious preinstall hook that downloads and executes an unverified Bun binary, then runs an 11.7 MB obfuscated payload designed to steal Kubernetes, Vault, cloud, GitHub, and CI/CD secrets. The attack closely overlaps with the SAP CAP, Cloud MTA, and lightning@2.6.2 compromises.

🚨 We’ve confirmed the intercom-client@7.0.4 was compromised in the ongoing Mini Shai-Hulud worm attack. The npm package includes a malicious preinstall hook that downloads and executes an unverified Bun binary, then runs an 11.7 MB obfuscated payload designed to steal Kubernetes, Vault, cloud, GitHub, and CI/CD secrets. The attack closely overlaps with the SAP CAP, Cloud MTA, and lightning@2.6.2 compromises.

WEIRD: 🇺🇸 DHS has issued hundreds of subpoenas to Meta, Reddit, Discord and others, to unmask anonymous accounts that criticize ICE.



“AI is making abuse easier and more damaging.” — Kalliopi Mingeirou, @UN_Women's Chief of the Ending Violence against Women Section. See why we're calling attention to online abuse in the #AI age: unwo.men/wILP50YTT3c #ACTtoEndViolence

🚨 The popular PyPI package lightning has been compromised in a supply chain attack. Socket detected malicious code in versions 2.6.2 and 2.6.3 that executes automatically on import, downloads Bun, and runs an 11 MB obfuscated JavaScript payload designed to steal credentials. This appears to be connected to yesterday's mini Shai-Hulud attack, but we're still investigating. #Python


One week after opening pre-orders, these are still selling extremely fast. We're now into Batch 10, which is our last August batch. We're going to do everything we can to scale manufacturing capacity to build these faster too!
















