⤷ Title: GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
Penetration Testing Tools
GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
GuardDog is a CLI tool that uses heuristics and Semgrep rules to scan for malicious npm, PyPI, Go, and VSCode packages, helping to secure the software supply chain.
⤷ Title: Hacked by Code We Trust: A Single Flaw Saved Your Data, analyzing the Amazon Injection Attack
════════════════════════
𐀪 Author: Harsh duhan
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 14:10:09 GMT
════════════════════════
⌗ Tags: #hacking #amazon_q #ai_agent #vscode #amazon
════════════════════════
𐀪 Author: Harsh duhan
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 14:10:09 GMT
════════════════════════
⌗ Tags: #hacking #amazon_q #ai_agent #vscode #amazon
Medium
Hacked by Code We Trust: A Single Flaw Saved Your Data, analyzing the Amazon Injection Attack
A Close Call: How a Malicious Pull Request Nearly Unleashed a Wiper Attack via Amazon Q Developer
⤷ Title: Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 23:27:39 GMT
════════════════════════
⌗ Tags: #information_security #ai #vscode #malware #cybersecurity
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 23:27:39 GMT
════════════════════════
⌗ Tags: #information_security #ai #vscode #malware #cybersecurity
Medium
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
Visual Studio Code (VS Code) has become the beating heart of modern software development — fast, flexible, and open. But new research from…
⤷ Title: Critical VSCode Supply Chain Flaw: 550+ Secrets Leaked Via Extensions, Exposing 100K+ Users to Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 03:49:08 +0000
════════════════════════
⌗ Tags: #Data Leak #AI API Keys #Dotfiles #Open VSX #PAT Leak #Secrets Management #supply chain attack #VSCode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 03:49:08 +0000
════════════════════════
⌗ Tags: #Data Leak #AI API Keys #Dotfiles #Open VSX #PAT Leak #Secrets Management #supply chain attack #VSCode
Daily CyberSecurity
Critical VSCode Supply Chain Flaw: 550+ Secrets Leaked Via Extensions, Exposing 100K+ Users to Malware
Wiz found 550+ secrets (PATs, API keys) leaked in 500+ VSCode extensions, enabling an attacker to push malicious updates to 100K+ developers. Dotfiles were the main culprit.
⤷ Title: TigerJack Hackers Use Malicious VSCode Extensions for Real-Time Code Theft and Cryptojacking on OpenVSX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 08:22:40 +0000
════════════════════════
⌗ Tags: #Malware #Backdoor #Code Theft #CoinIMP #Cryptojacking #Extension Supply Chain #OpenVSX #TigerJack #VSCode
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 08:22:40 +0000
════════════════════════
⌗ Tags: #Malware #Backdoor #Code Theft #CoinIMP #Cryptojacking #Extension Supply Chain #OpenVSX #TigerJack #VSCode
Penetration Testing Tools
TigerJack Hackers Use Malicious VSCode Extensions for Real-Time Code Theft and Cryptojacking on OpenVSX
The TigerJack group is attacking developers via malicious VSCode extensions on OpenVSX. Plugins secretly steal C++ source code in real-time and deploy the CoinIMP cryptojacker.
⤷ Title: GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:40:52 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #GlassWorm #HVNC #Solana Blockchain #supply chain attack #Unicode Injection #VSCode #ZOMBI RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:40:52 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #GlassWorm #HVNC #Solana Blockchain #supply chain attack #Unicode Injection #VSCode #ZOMBI RAT
Daily CyberSecurity
GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2
Koi Security exposed GlassWorm, the first VSCode worm that spreads autonomously, using invisible Unicode to hide malicious code. It uses Solana blockchain and Google Calendar for a resilient C2.
⤷ Title: VSCode Supply Chain Compromise: 12 Malicious Extensions Steal Source Code and Open Remote Shells
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Malicious Extension #Ngrok #Remote Shell #Source Code Theft #supply chain attack #VSCode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Malicious Extension #Ngrok #Remote Shell #Source Code Theft #supply chain attack #VSCode
Daily CyberSecurity
VSCode Supply Chain Compromise: 12 Malicious Extensions Steal Source Code and Open Remote Shells
HelixGuard exposed a VSCode supply chain attack using 12 malicious extensions. They steal source code, capture screenshots, and open reverse shells via Ngrok and AWS EC2 to compromise developers.
⤷ Title: The VS Code Trojan: How GlassWorm Infected 35,000 Developer Machines
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 06:33:15 GMT
════════════════════════
⌗ Tags: #supply_chain_attack #trojan #vscode #cybersecurity #malware
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 06:33:15 GMT
════════════════════════
⌗ Tags: #supply_chain_attack #trojan #vscode #cybersecurity #malware
Medium
The VS Code Trojan: How GlassWorm Infected 35,000 Developer Machines
A sophisticated malware campaign is hijacking developers through their favorite IDE
⤷ Title: SleepyDuck VSX Malware Leverages Ethereum Blockchain for Command Server Persistence
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 07:46:35 GMT
════════════════════════
⌗ Tags: #blockchain #malware #cryptocurrency #vscode_extension #hacking
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 07:46:35 GMT
════════════════════════
⌗ Tags: #blockchain #malware #cryptocurrency #vscode_extension #hacking
Medium
SleepyDuck VSX Malware Leverages Ethereum Blockchain for Command Server Persistence
Cybersecurity researchers have flagged a new malicious extension in the Open VSX registry that harbors a Remote Access Trojan (RAT) called…
⤷ Title: GlassWorm Worm Resurfaces: Invisible Unicode Malware Re-Infects VS Code Extensions, Spreads to GitHub
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:31:19 +0000
════════════════════════
⌗ Tags: #Malware #Code Theft #GitHub Compromise #GlassWorm #Solana C2 #supply chain attack #Unicode Worm #VSCode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:31:19 +0000
════════════════════════
⌗ Tags: #Malware #Code Theft #GitHub Compromise #GlassWorm #Solana C2 #supply chain attack #Unicode Worm #VSCode
Daily CyberSecurity
GlassWorm Worm Resurfaces: Invisible Unicode Malware Re-Infects VS Code Extensions, Spreads to GitHub
GlassWorm resurfaced, infecting 3 new VS Code extensions on OpenVSX. The worm uses invisible Unicode and Solana blockchain C2 to steal credentials and spread via AI-generated malicious commits on GitHub.
⤷ Title: Membongkar Celah Keamanan SQL Injection: Eksperimen Praktis pada Database Web Menggunakan XAMPP dan…
════════════════════════
𐀪 Author: Maulanahandayani
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 17:24:31 GMT
════════════════════════
⌗ Tags: #sql_injection #membongkar_celah_keamanan #xampp_server #vscode
════════════════════════
𐀪 Author: Maulanahandayani
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 17:24:31 GMT
════════════════════════
⌗ Tags: #sql_injection #membongkar_celah_keamanan #xampp_server #vscode
Medium
Membongkar Celah Keamanan SQL Injection: Eksperimen Praktis pada Database Web Menggunakan XAMPP dan…
Maulana Malik Ibrahim
⤷ Title: Eksperimen Ngebobol dan Nambal Celah SQL Injection
════════════════════════
𐀪 Author: ica rizqiah
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 09:03:35 GMT
════════════════════════
⌗ Tags: #programming #sql_injection #vscode #website_development #cybersecurity
════════════════════════
𐀪 Author: ica rizqiah
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 09:03:35 GMT
════════════════════════
⌗ Tags: #programming #sql_injection #vscode #website_development #cybersecurity
Medium
Eksperimen Ngebobol dan Nambal Celah SQL Injection
Pernah nggak sih kalian nemuin halaman login web yang UI-nya estetik banget, warnanya ungu pastel gemoy, dan kelihatan super aman? Buat…
⤷ Title: Vibe Coding is Over! Here’s What Comes Next.
════════════════════════
𐀪 Author: Priyanshu Sahu
════════════════════════
ⴵ Time: Tue, 19 May 2026 21:15:05 GMT
════════════════════════
⌗ Tags: #programming #bug_bounty #coding #vscode #vibe_coding
════════════════════════
𐀪 Author: Priyanshu Sahu
════════════════════════
ⴵ Time: Tue, 19 May 2026 21:15:05 GMT
════════════════════════
⌗ Tags: #programming #bug_bounty #coding #vscode #vibe_coding
Medium
Vibe Coding is Over! Here’s What Comes Next.
“I Was a Vibe Coder. Here Is What Broke Me Out of It.”
⤷ Title: Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 06:45:58 +0000
════════════════════════
⌗ Tags: #Malware #AppleSeed #cyber_espionage #HelloDoor #infosec #Kimsuky #MemLoad #PebbleDash #Rust Backdoor #threat intelligence #TryCloudflare #VSCode Remote Tunneling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 06:45:58 +0000
════════════════════════
⌗ Tags: #Malware #AppleSeed #cyber_espionage #HelloDoor #infosec #Kimsuky #MemLoad #PebbleDash #Rust Backdoor #threat intelligence #TryCloudflare #VSCode Remote Tunneling
Daily CyberSecurity
Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling
Kimsuky APT evolves its arsenal with "HelloDoor," a new Rust-based backdoor, and hijacks trusted VSCode Remote Tunneling to bypass corporate firewalls.
⤷ Title: Architectural Collapse: How Extension Poisoning, Node Vulnerabilities, and Infrastructure Fog…
════════════════════════
𐀪 Author: Akash Lomas
════════════════════════
ⴵ Time: Mon, 25 May 2026 07:38:52 GMT
════════════════════════
⌗ Tags: #github #npm #vulnerability #hacking #vscode
════════════════════════
𐀪 Author: Akash Lomas
════════════════════════
ⴵ Time: Mon, 25 May 2026 07:38:52 GMT
════════════════════════
⌗ Tags: #github #npm #vulnerability #hacking #vscode
Medium
Architectural Collapse: How Extension Poisoning, Node Vulnerabilities, and Infrastructure Fog…
Enterprise perimeter defenses are fundamentally built on an obsolete assumption that, the developer’s workstation is a secure, trusted…
⤷ Title: Critical GitHub Token Stealing Bug Exploits Web-Based Code Editors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 02:18:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Ammar Askar #Browser Sandbox #github.dev #token exfiltration #VSCode vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 02:18:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Ammar Askar #Browser Sandbox #github.dev #token exfiltration #VSCode vulnerability
Daily CyberSecurity
Critical GitHub Token Stealing Bug Exploits Web-Based Code Editors
A critical GitHub token stealing bug targets github.dev web spaces. Learn how it exploits the VSCode webview security model to hijack private repositories.