Daily Writeups
3.54K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Python Developers Beware: These Innocent PyPI Packages Secretly Hijack Your System with Deadly RAT!
════════════════════════
𐀪 Author: cybrNK
════════════════════════
Time: Sat, 20 Sep 2025 19:35:46 GMT
════════════════════════
Tags: #trojan #hacking #pypi #python #cybersecurity
Title: PyPI Under Attack: New Malware ‘SilentSync’ Is Stealing Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 22 Sep 2025 00:20:49 +0000
════════════════════════
Tags: #Malware #cybersecurity #Linux #macOS #PyPI ecosystem #Python #rat #SilentSync malware #supply chain attack #windows #Zscaler ThreatLabz
Title: PSF Warns of Fake PyPI Login Site Stealing User Credentials
════════════════════════
𐀪 Author: Waqas
════════════════════════
Time: Wed, 24 Sep 2025 17:22:32 +0000
════════════════════════
Tags: #Security #Phishing Scam #Cyber Attack #Cybersecurity #Developers #Privacy #PSF #PyPI #Scam #security #Software
Title: New Phishing Campaign Targets PyPI Maintainers with Fake Domain
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Sep 2025 00:14:30 +0000
════════════════════════
Tags: #Cybercriminals #cybersecurity #developer #open_source #phishing #PyPI #supply chain attack
Title: GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
Title: Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
Title: PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
Title: Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 10 Feb 2026 00:12:25 +0000
════════════════════════
Tags: #Malware #cryptocurrency #DeFi Security #dYdX #npm malware #PyPi Malware #Python RAT #Remote Access Trojan #Socket Security #supply chain attack #Typosquatting #Wallet Stealer
Title: Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Title: Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Title: AI’s Supply Chain Nightmare: The Lightning Framework Worm and the “Silence Developer” Meme
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sat, 02 May 2026 03:10:13 +0000
════════════════════════
Tags: #Malware #AI security #Cloud Secrets #cyber_espionage #GitHub Compromise #infosec #LAPSUS$ #Lightning AI #malware #PyPI Security #supply chain attack #TEAM PCP
Title: New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 06 May 2026 08:11:06 +0000
════════════════════════
Tags: #Malware #AWS Credentials #DevOps Security #eBPF Rootkit #Fileless Malware #infosec #Linux RAT #npm Security #PyPI #QLNX #Quasar Linux #supply chain attack #Trend Micro
Title: OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API