#atomdrift — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #atomdrift, aggregated by home.social.
-
Now witness the firepower of this fully armed and operational #malware analysis cluster. 1TB of RAM, 478 cores, 4 operating systems. #atomdrift
-
I went overboard on the new #atomdrift #ZFS storage server (128-core ARM64, 128TB of storage, 256GB of RAM), so I felt it was necessary to do the same with the MOTD.
-
Multiple security vendors reached out this week about integrating #atomdrift.
One asked: "What are your project's principles?". So now we have some:
-
In starting #Atomdrift - I've been driven by a single goal: reliably detect the next xzutils-style supply-chain attack, whether created by a human or AI. Our #Scan project was phase 1, and now we're looking for design partners for phase 2. If interested or just curious, DM me.
(Yes, this is a shitty LLM-generated image based on its design doc; plz roast)
-
As much as I dislike whoring myself out like this, I could use some help!
#atomdrift just relocated from codeberg to github; so all of our "stars" reset. If you have a GitHub account, take a moment to star our project: https://github.com/atomdrift-project/scan - for better or worse, folks use stars to determine whether a project is worthwhile; this one certainly is.
-
#atomdrift scan now has pre-built binaries and an installer - go try it! https://install.atomdrift.org/ - yes, it's curl|sh; but what else are you gonna do?
My favorite part was adding support for as many platforms as I could. I haven't found a usable Rust 1.94 build for #HaikuOS or GNU #Hurd yet; but otherwise it probably supports your platform of choice. Still waiting on #Apple for notarization - feedback welcome!
-
I was getting worried about #atomdrift's false-positive rates climbing, so I dug into the data this morning and found 4 more undiscovered #malware samples in the test data :(
Ugh. Data quality is everything. 🤦
-
For the last month, I've been vacationing in Europe, now currently on the lovely island of Naxos in Greece - which has been amazing. It's hard to imagine what life will feel like when I get home and need to push hard to turn this crazy #atomdrift idea into a sustainable income.
One surprise is how much history @ariadne has here: https://en.wikipedia.org/wiki/Naxos#History - not to mention the tiny elephants!
-
I've been trying to stay quiet about it over vacation, but I'm damned impressed with how #atomdrift is showing up in the malware detection charts. Nothing comes close to it for #supplychainsecurity. Have a question? Leave a comment.
-
Things are not looking so good for the Linux box that serves the #atomdrift API for serving, foraging, and generally managing sample files.
Definitely a shame to be 7000km away from the power button for the next 3 weeks, as it doesn't respond to soft reboot requests.
Kinda wish I'd gotten around to enabling remote ZFS snapshots before I left. 🤦
-
-
Anyone have security contacts at #ArchLinux? #atomdrift is finding new malware samples almost every hour and I would love to find a way to coordinate in real-time.
-
We don't see too many supply-chain attacks against the #rust crates.io ecosystem; but they are out there! Today's victim is the #onering crate, and everyone who uses it - the crate now uploads the contents of the users last git commit via HTTPS at build time.
Detected using open-source - #atomdrift - https://atomdrift.org/discoveries/2026/06/onering-source-leak/
-
With #atomdrift - we're detecting a dozen new supply-chain attacks every day; on-par with the commercial vendors. Most are boring, but some are brazen - this attempt at a CDN-distributed #cryptojacker is the latter: https://atomdrift.org/discoveries/2026/06/v018-axios-cdntest-c-is-for-cookie/
-
The best part of being a solo-founder is the ability to take guilt-free thinking rides. It gave me the clarity on what I'd like to ship next for #atomdrift - JSON trait context, improved lab interface, and a --second-opinion option for (local but non-deterministic) LLM assistance. Coming to #litmus soon!
-
One of my favorite features with #atomdrift's approach to supply-chain attack decomposition is the ability to quickly find other samples using the same techniques by clicking on the #malecule - our custom hash based on a program's behavioral profile. This NPM was uploaded just a few minutes ago, but matches many attacks we've seen throughout the last month.
-
Now that #atomdrift is ingesting 2TB a month of new open-source software releases (HOLY FUCKING HELL) as training data, I now get why nobody is doing open-source supply-chain detection.
I think we're going to need a bigger boat.
-
Posting about every malicious NPM package discovered by #atomdrift is going to get old real quick (>4 a day!); so I'm going to keep my trap shut after this one unless something really exciting pops up.
hashtag#atomdrift is now monitoring 100+ software marketplaces; from NetBSD to PortableApps. Come check it out: https://atomdrift.org/
-
One of the crazier ideas I've had while working on #atomdrift is using adversarial local LLMs to generate synthetic malware in bulk. I'm using this to stress-test our rules on never-before-seen samples; and to fill in the gaps for languages with a limited malware corpus (zig, groovy, lua, etc.).
For the limited set I've tried in a VM, they work too! Scary.
-
After being hosed by #btrfs on #linux 7.0.1, the #atomdrift postgresql master database is on #OmniOS & #ZFS
It's good to be back, even if I'm rusty in Solaris-based environments.
-
Would #atomdrift #cleave have detected today's supply-chain attack against the PyPI lightning package? Yup.
-
Buying a relatively modern ThreadRipper was the best decision yet for the #atomdrift project; it's hard to argue with 128 threads.
I could have saved myself at least 2 weeks of development time if I had bought it two months ago.
-
It took me an embarrassingly long time to get here, but I now have a fast, fully distributed #malware training system running out of my #homelab - it's open source too! The next #atomdrift release drops tomorrow (once training completes).
In the meantime, it's time to scour eBay for more hardware!
-
This poor ThreadRipper is running like this 24/7 nowadays, all in the name of improving the ability for #opensource projects to detect supply-chain attacks. I guess it's time for #atomdrift to go distributed.
-
At the risk of spilling the beans too early... I grew tired of the constant barrage of supply-chain attacks afflicting the open-source community and decided to create a new open-source #malware scanner, named #Litmus.
This is part of a larger vision for intercepting supply-chain attacks, called The #Atomdrift Project. I want to empower everyone, from software marketplaces to teenagers at home, to catch the sorts of attacks we've recently seen against #Trivy and #OpenClaw.
-
Preview results for the initial #litmus model for malicious supply-chain attack detection from Project #Atomdrift - based on the 10 most recent malware samples from 10 different threat feeds.
I'm EXTREMELY happy with this outcome. There are 26 hours left for the first training run to complete (which excludes these samples), so maybe the full model will knock out another 2-3 more.
-
Throughout 2026, I've been working hard on a project to make open-source #malware detection useful and tractable: not just for random Win32 or #macOS binaries, but for supply-chain attacks like xzutils or random #OpenClaw fuckery. Tomorrow, I finally get to share my work. #atomdrift