Daily Writeups
3.52K subscribers
2 photos
129K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
Title: Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
Title: PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
Title: Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 10 Feb 2026 00:12:25 +0000
════════════════════════
Tags: #Malware #cryptocurrency #DeFi Security #dYdX #npm malware #PyPi Malware #Python RAT #Remote Access Trojan #Socket Security #supply chain attack #Typosquatting #Wallet Stealer
Title: Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Title: Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Title: AI’s Supply Chain Nightmare: The Lightning Framework Worm and the “Silence Developer” Meme
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 02 May 2026 03:10:13 +0000
════════════════════════
Tags: #Malware #AI security #Cloud Secrets #cyber_espionage #GitHub Compromise #infosec #LAPSUS$ #Lightning AI #malware #PyPI Security #supply chain attack #TEAM PCP
Title: New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 08:11:06 +0000
════════════════════════
Tags: #Malware #AWS Credentials #DevOps Security #eBPF Rootkit #Fileless Malware #infosec #Linux RAT #npm Security #PyPI #QLNX #Quasar Linux #supply chain attack #Trend Micro
Title: OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API
Title: Google Says Hackers Used AI to Develop a Zero-Day Exploit
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
Time: Mon, 11 May 2026 22:00:41 +0000
════════════════════════
Tags: #Security #Artificial Intelligence #0day #AI #Android #backdoor #Cyber Attack #Cybersecurity #GitHub #Google #Malware #PyPI #Vulnerability
Title: TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
Time: Wed, 13 May 2026 15:18:47 +0000
════════════════════════
Tags: #Security #Malware #Cyber Attack #Mini Shai_Hulud #NPM #PyPI #Supply Chain #TeamPCP
Title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
════════════════════════
𐀪 Author: Waqas
════════════════════════
Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack (Updated)
════════════════════════
𐀪 Author: Waqas
════════════════════════
Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
Title: Dependabot and PyPI Add Supply Chain Cooldowns
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
Time: Wed, 29 Jul 2026 06:34:12 +0000
════════════════════════
Tags: #Malware #cybersecurity #Dependabot #Github #PyPI #Supply Chain Security
Title: Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
════════════════════════
𐀪 Author: Waqas
════════════════════════
Time: Fri, 31 Jul 2026 20:01:51 +0000
════════════════════════
Tags: #Data Breaches #Artificial Intelligence #Hacking News #Security #Anthropic #Claude #Claude Mythos 5 #Claude Opus 4.7 #Cyber Attack #Cybersecurity #hacking #Hugging Face #Mythos #OpenAI #PyPI #Vulnerability