Daily Writeups
3.89K subscribers
4 photos
134K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
⤷ Title: Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
⤷ Title: PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
⤷ Title: Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:12:25 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #DeFi Security #dYdX #npm malware #PyPi Malware #Python RAT #Remote Access Trojan #Socket Security #supply chain attack #Typosquatting #Wallet Stealer
⤷ Title: Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
⌗ Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
⤷ Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
⤷ Title: Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
⤷ Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
⤷ Title: AI’s Supply Chain Nightmare: The Lightning Framework Worm and the “Silence Developer” Meme
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:10:13 +0000
════════════════════════
⌗ Tags: #Malware #AI security #Cloud Secrets #cyber_espionage #GitHub Compromise #infosec #LAPSUS$ #Lightning AI #malware #PyPI Security #supply chain attack #TEAM PCP
⤷ Title: New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:11:06 +0000
════════════════════════
⌗ Tags: #Malware #AWS Credentials #DevOps Security #eBPF Rootkit #Fileless Malware #infosec #Linux RAT #npm Security #PyPI #QLNX #Quasar Linux #supply chain attack #Trend Micro
⤷ Title: OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API
⤷ Title: Google Says Hackers Used AI to Develop a Zero-Day Exploit
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:00:41 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #0day #AI #Android #backdoor #Cyber Attack #Cybersecurity #GitHub #Google #Malware #PyPI #Vulnerability
⤷ Title: TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 13 May 2026 15:18:47 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Mini Shai_Hulud #NPM #PyPI #Supply Chain #TeamPCP
⤷ Title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
⤷ Title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack (Updated)
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
⤷ Title: Dependabot and PyPI Add Supply Chain Cooldowns
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 06:34:12 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Dependabot #Github #PyPI #Supply Chain Security
⤷ Title: Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 20:01:51 +0000
════════════════════════
⌗ Tags: #Data Breaches #Artificial Intelligence #Hacking News #Security #Anthropic #Claude #Claude Mythos 5 #Claude Opus 4.7 #Cyber Attack #Cybersecurity #hacking #Hugging Face #Mythos #OpenAI #PyPI #Vulnerability
⤷ Title: PyPI File Hosting Errors: 502s Traced to Fastly Cache
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 08 Sep 2026 15:35:13 +0000
════════════════════════
⌗ Tags: #Technology #502 error #Fastly CDN #file hosting errors #PyPI #Python Package Index #Software Supply Chain
⤷ Title: The ‘sckit’ Worm Bridges the npm and PyPI Divide
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 06:50:29 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #npm #PyPI #supply chain attack