⤷ Title: Easiest way to Find RCE (Package Dependency)
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Fri, 28 Feb 2025 03:56:24 GMT
════════════════════════
⌗ Tags: #package_dependency #cybersecurity #bug_bounty #rce #bug_bounty_writeup
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Fri, 28 Feb 2025 03:56:24 GMT
════════════════════════
⌗ Tags: #package_dependency #cybersecurity #bug_bounty #rce #bug_bounty_writeup
Medium
Easiest way to Find RCE (Package Dependency)
Free Article
⤷ Title: Malicious NPM Packages Target PayPal Users to Steal Sensitive Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 00:16:26 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Data Theft #dependency confusion #FortiGuard Labs #Information stealing #javascript #Malicious packages #npm #NPM packages #Package manager #paypal #Software security #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 00:16:26 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Data Theft #dependency confusion #FortiGuard Labs #Information stealing #javascript #Malicious packages #npm #NPM packages #Package manager #paypal #Software security #supply chain attack
Daily CyberSecurity
Malicious NPM Packages Target PayPal Users to Steal Sensitive Data
FortiGuard Labs discovers malicious NPM packages targeting PayPal users. Attackers use deceptive tactics to steal usernames, paths, and hostnames
⤷ Title: Malicious npm Packages Backdoor Telegram Bot Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:12:46 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #malware #Node.js #npm #package security #Software security #ssh backdoor #supply chain attack #Telegram Bots
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:12:46 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #malware #Node.js #npm #package security #Software security #ssh backdoor #supply chain attack #Telegram Bots
Daily CyberSecurity
Malicious npm Packages Backdoor Telegram Bot Developers
Malicious npm packages are targeting Telegram bot developers, installing SSH backdoors and stealing data. Learn how this supply chain attack works and how to protect yourself.
⤷ Title: dpkg-deb Flaw Opens Path to Disk Exhaustion Denial-of-Service on Debian Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 00:22:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Debian #Denial of Service #Disk Quota #dos #dpkg_deb #Linux #Package Management #Temporary Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 00:22:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Debian #Denial of Service #Disk Quota #dos #dpkg_deb #Linux #Package Management #Temporary Files
Daily CyberSecurity
dpkg-deb Flaw Opens Path to Disk Exhaustion Denial-of-Service on Debian Systems
A flaw (CVE-2025-6297, CVSS 8.2) in dpkg-deb allows DoS via disk quota exhaustion by leaving temporary files. Update immediately to prevent system instability.
⤷ Title: How to Fix the “NO_PUBKEY” Error in Kali Linux
════════════════════════
𐀪 Author: Uzoukwu Eric Ikenna
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:57:20 GMT
════════════════════════
⌗ Tags: #package_management #gpg_key #linux #cybersecurity #linux_troubleshooting
════════════════════════
𐀪 Author: Uzoukwu Eric Ikenna
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:57:20 GMT
════════════════════════
⌗ Tags: #package_management #gpg_key #linux #cybersecurity #linux_troubleshooting
Medium
How to Fix the “NO_PUBKEY” Error in Kali Linux
Resolve GPG key issues in Kali Linux and keep your system secure and up to date.
⤷ Title: Helm Flaw (CVE-2025-53547): Local Code Execution via Malicious Chart.yaml & Symlinks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chart.lock #Chart.yaml #CVE_2025_53547 #cybersecurity #Kubernetes #LCE #Local Code Execution #Package manager #Symlinks #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chart.lock #Chart.yaml #CVE_2025_53547 #cybersecurity #Kubernetes #LCE #Local Code Execution #Package manager #Symlinks #Vulnerability
Daily CyberSecurity
Helm Flaw (CVE-2025-53547): Local Code Execution via Malicious Chart.yaml & Symlinks
A flaw in Helm (CVE-2025-53547, CVSS 8.5) allows local code execution when updating dependencies via a malicious Chart.yaml and symlinked Chart.lock file
⤷ Title: PyPI Bans Inbox.ru After Massive Spam Campaign and 1,500+ Fake Project Uploads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 01:40:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #inbox.ru #open_source #Package Impersonation #PyPI #Python Package Index #Slopsquatting #Spam #Supply Chain Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 01:40:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #inbox.ru #open_source #Package Impersonation #PyPI #Python Package Index #Slopsquatting #Spam #Supply Chain Security
Daily CyberSecurity
PyPI Bans Inbox.ru After Massive Spam Campaign and 1,500+ Fake Project Uploads
PyPI has banned inbox.ru registrations after a large-scale spam campaign created over 1,500 fake projects, exploiting name confusion and impersonation.
⤷ Title: How to Migrate Your Vite + React + TypeScript Project from npm to Yarn (The Clean Way)
════════════════════════
𐀪 Author: AIAlchemist_Ab1r
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 08:39:14 GMT
════════════════════════
⌗ Tags: #seo #software_development #package_management #webdev #hacking
════════════════════════
𐀪 Author: AIAlchemist_Ab1r
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 08:39:14 GMT
════════════════════════
⌗ Tags: #seo #software_development #package_management #webdev #hacking
Medium
🚀 How to Migrate Your Vite + React + TypeScript Project from npm to Yarn (The Clean Way)
Slow builds, inconsistent dependencies, and unpredictable CI/CD pipelines can cost enterprise dev teams hours — or even days — per month…
⤷ Title: Typosquatting in Package Managers: The Attack That Preys on a Single Keystroke
════════════════════════
𐀪 Author: InstaTunnel
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 07:55:34 GMT
════════════════════════
⌗ Tags: #malicious_package #typosquatting #package_manager #cybersecurity #supply_chain_attack
════════════════════════
𐀪 Author: InstaTunnel
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 07:55:34 GMT
════════════════════════
⌗ Tags: #malicious_package #typosquatting #package_manager #cybersecurity #supply_chain_attack
Medium
Typosquatting in Package Managers: The Attack That Preys on a Single Keystroke
⤷ Title: 373 Malicious Packages a Day: Why Software Supply Chain Compromise Is Inevitable
════════════════════════
𐀪 Author: Peter Hanneman
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 23:39:55 GMT
════════════════════════
⌗ Tags: #software_development #cyber_security_awareness #package_manager #web_development #cybersecurity
════════════════════════
𐀪 Author: Peter Hanneman
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 23:39:55 GMT
════════════════════════
⌗ Tags: #software_development #cyber_security_awareness #package_manager #web_development #cybersecurity
Medium
373 Malicious Packages a Day: Why Software Supply Chain Compromise Is Inevitable
Antivirus, firewalls and paranoia aren’t enough to protect you from software supply chain attacks.
⤷ Title: Alpine Linux 3.23 Released: Adopts 6.18 LTS Kernel & Unveils APK 3.0 Package Manager
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:31:10 +0000
════════════════════════
⌗ Tags: #Linux #Alpine Linux #APK 3.0.0 #Containers #Linux 3.23 #Linux 6.18 #LTS Kernel #Minimalist OS #musl libc #Package Manager
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:31:10 +0000
════════════════════════
⌗ Tags: #Linux #Alpine Linux #APK 3.0.0 #Containers #Linux 3.23 #Linux 6.18 #LTS Kernel #Minimalist OS #musl libc #Package Manager
Penetration Testing Tools
Alpine Linux 3.23 Released: Adopts 6.18 LTS Kernel & Unveils APK 3.0 Package Manager
The latest cycle of updates within the Linux distribution ecosystem closes the year with a notable milestone: Alpine
⤷ Title: The Trojan Coding Assistant: How a Compromised Token Pushed a Shadow Release of Cline
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:15:17 +0000
════════════════════════
⌗ Tags: #Malware #Cline CLI #GitHub Actions #npm security #OIDC #OpenClaw #package.json #software provenance #supply chain attack #Tech News 2026 #web shells
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:15:17 +0000
════════════════════════
⌗ Tags: #Malware #Cline CLI #GitHub Actions #npm security #OIDC #OpenClaw #package.json #software provenance #supply chain attack #Tech News 2026 #web shells
Penetration Testing Tools
The Trojan Coding Assistant: How a Compromised Token Pushed a Shadow Release of Cline
An incident has transpired within the npm registry involving the Cline CLI utility; for a duration of several
⤷ Title: Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 04:25:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET Security #Financial Cybercrime #infosec #malware #NuGet #Package Impersonation #ReversingLabs #Stripe.net #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 04:25:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET Security #Financial Cybercrime #infosec #malware #NuGet #Package Impersonation #ReversingLabs #Stripe.net #supply chain attack #Typosquatting
Daily CyberSecurity
Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain
ReversingLabs uncovers a malicious NuGet package mimicking Stripe.net. Discover how attackers are targeting the financial sector via supply chain poisoning.
⤷ Title: Root Access at Risk: Critical Nix Sandbox Escape Overwrites Sensitive System Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 13:03:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_39860 #infosec #Linux Security #Nix #NixOS #Package Management #privilege escalation #root access #Sandbox Escape
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 13:03:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_39860 #infosec #Linux Security #Nix #NixOS #Package Management #privilege escalation #root access #Sandbox Escape
Daily CyberSecurity
Root Access at Risk: Critical Nix Sandbox Escape Overwrites Sensitive System Files
Nix patches a critical 9.0 CVSS sandbox escape. Learn how CVE-2026-39860 allows unprivileged users to seize root control via symlink manipulation. Update now!
⤷ Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
Penetration Testing Tools
RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
RubyGems has temporarily suspended the registration of new accounts following a pervasive assault on the Ruby ecosystem. According
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: Google Wallet Package Tracking Turns Your Gmail Receipts Into Delivery Cards
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 03:50:11 +0000
════════════════════════
⌗ Tags: #Technology #android #Apple Wallet #Digital Wallet #gmail #Google Wallet #Package Tracking
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 03:50:11 +0000
════════════════════════
⌗ Tags: #Technology #android #Apple Wallet #Digital Wallet #gmail #Google Wallet #Package Tracking
Daily CyberSecurity
Google Wallet Package Tracking Turns Your Gmail Receipts Into Delivery Cards
Google has just rolled out a genuinely useful addition to Google Wallet: package tracking. Thanks to deep Gmail integration, the app can now read your online shopping receipts and tracking codes a…