
VIVEK MALIK
1.4K posts

VIVEK MALIK
@vivek_malik
Software Developer. Security Researcher, and enthusiast. Passionate Arsenal Fan Always Follow back all gooners. Retweet != endorsement




THIS IS ACTUALLY INSANE!🤯 The FBI launched its own crypto token last year just to trap the scammers. They were sick of pump and dumps. So they built a real token with a real site and real branding, called it NexFundAI, and waited to see who would show up. Within weeks, scammers were lining up to fake the volume for undercover agents. Then one of them got on a recorded call and said it out loud. Their entire business model was making regular people lose money so they could profit. The FBI had all of it on tape. 18 charged. $25M seized. Arrests across 3 countries. The wildest part? The FBI ran a cleaner crypto project than half the founders out there. And the whole thing was a trap from day one.







‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.


SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.



This attack leveraged GitHub Actions Cache Poisoning. Payload deployed here: github.com/TanStack/route… It looks like it detonated here: #step:26:2" target="_blank" rel="nofollow noopener">github.com/TanStack/route…

macOS labs in THL just got a real upgrade. We’ve released guided macOS investigation help for supported labs, giving learners better structure while they work through unfamiliar telemetry. This includes: - macOS telemetry orientation - question-level investigation guidance - field and artifact explanations - common mistake callouts - methodology-focused debriefs - better support for learning the workflow, not memorizing answers macOS intrusion investigations need their own muscle memory. You need to understand where process activity shows up, how shell behavior looks, where collection and staging evidence tends to appear, and how to validate the sequence without assuming Windows patterns apply. That is what this update is designed to support. Tomorrow, a new investigation will make that much more concrete! Check out our labs -> threathuntinglabs.com/threat-hunting

Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised & seen scanning our honeypots on 2026-04-30. Follow latest guidance to track for compromise & patch: support.cpanel.net/hc/en-us/artic… See Public Dashboard for stats: dashboard.shadowserver.org/statistics/hon…





